Impact
The vulnerability arises when the Okta Verify for Windows uninstaller does not validate that the user data directory is a filesystem junction before deleting its contents. Because the delete operation follows the junction target, it can recursively remove content in directories that are not intended to be deleted. This results in unintended data loss or removal of user data from locations outside the application data area, presenting a moderate security consequence as it can affect confidentiality and availability for user files. The weakness is identified as improper handling of resource references (CWE-59).
Affected Systems
Okta Verify for Windows, all installations that use the uninstaller component where the user data directory might be a junction. Users of Okta Verify 7.0.0 and newer are not impacted as the issue has been fixed in those releases.
Risk and Exploitability
The vulnerability is assessed with a CVSS score of 6, indicating medium severity. EPSS data is not available, so the current probability of exploitation is unknown, though the lack of a public exploit and the unpatched risk suggest a relatively low likelihood until an exploit emerges. The vulnerability is not listed in the CISA KEV catalog. Exploitation would likely require a user or attacker with the ability to initiate the uninstall process with elevated privileges on the target Windows machine, which could be achieved locally or remotely if privilege escalation is possible. Once triggered, the uninstaller would delete files under any junctioned directories, leading to loss of data that may be critical for the user or organization.
OpenCVE Enrichment