Impact
The Okta Hyperdrive Integration plugin resolves a required assembly with a registry path that resides in the current user's hive, without performing integrity checks. The referenced path is then loaded via Assembly.LoadFrom, which does not verify the assembly's digital signature. As a result, an untrusted DLL can be executed within the context of the host process or even an elevated installer, allowing arbitrary code execution at the privilege level of the running process. This flaw corresponds to the coalition of untrusted file or resource injection weaknesses and can lead to complete loss of confidentiality, integrity, and availability of the affected system.
Affected Systems
The vulnerability affects the Okta Hyperdrive Integration plugin, as identified by the CNA. No specific version information is included in the provided data, so all current or older installations of this plugin are potentially impacted until the fix is applied.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity risk, though the EPSS score is not provided, and the issue is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is that an attacker who can influence the registry settings or supply a malicious assembly will trigger the plugin to load the unverified DLL, resulting in remote code execution. The flaw requires that the attacker can provide the DLL and influence the plugin’s registry path resolution—conditions that might be met by compromising the host or modifying the plugin configuration.
OpenCVE Enrichment