CVE-2026-2999
Critical
|9.3Exploit Available
Plain English Summary
AI-powered analysis for quick understanding
This vulnerability allows attackers to remotely execute malicious programs on a system without needing any authentication. They can trick the system into downloading and running harmful files from the internet, making it critical to secure the affected software.
Technical Description
IDExpert Windows Logon Agent developed by Changing has a Remote Code Execution vulnerability, allowing unauthenticated remote attackers to force the system to download arbitrary executable files from a remote source and execute them.
CVSS Vector Analysis
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
Confidentiality ImpactHigh
Integrity ImpactHigh
Availability ImpactHigh
ScopeChanged
Vector String
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XExploit Resources
Search for proof-of-concept code and exploit modules
Official References
Est. Bounty
$8,000($5K-$15K)
Vendor Response
Grade APatched in 0 days
Quick Information
Published
Mar 2, 2026
about 1 month ago
Last Modified
Mar 2, 2026
about 1 month ago