CVE-2026-3000
Received
Received - Intake
Remote Code Execution in IDExpert Windows Logon Agent
Publication date: 2026-03-02
Last updated on: 2026-03-09
Assigner: TWCERT/CC
Description
Description
IDExpert Windows Logon Agent developed by Changing has a Remote Code Execution vulnerability, allowing unauthenticated remote attackers to force the system to download arbitrary DLL files from a remote source and execute them.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| changingtec | idexpert | From 2.7.3.230719 (inc) to 2.8.4.250925 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-494 | The product downloads source code or an executable from a remote location and executes the code without sufficiently verifying the origin and integrity of the code. |