PingID Windows Login prior to 2.8 uses known vulnerable components that can lead to remote code execution
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.6epss 1.9%
exploitation probability
1.9%top 22% of all CVEs
observed exploitation
nono source reports it
PingID Windows Login prior to 2.8 uses known vulnerable components that can lead to remote code execution. An attacker capable of achieving a sophisticated man-in-the-middle position, or to compromise Ping Identity web servers, could deliver malicious code that would be executed as SYSTEM by the PingID Windows Login application.
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
Affected products
Ping Identity · PingID Windows Login