CVE-2026-2999 PUBLISHED

Changing|IDExpert Windows Logon Agent - Remote Code Execution

Assigner: twcert
Reserved: 23.02.2026 Published: 02.03.2026 Updated: 02.03.2026

IDExpert Windows Logon Agent developed by Changing has a Remote Code Execution vulnerability, allowing unauthenticated remote attackers to force the system to download arbitrary executable files from a remote source and execute them.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor Changing
Product IDExpert Windows Logon Agent
Versions Default: unaffected
  • affected from 2.7.3.230719 to 2.8.4.250925 (incl.)

Solutions

Contact the vendor to patch or download the patch from the official website. Link: https://www.changingtec.com/news_detail.jsp?item_id=348

References

Problem Types

  • CWE-494 Download of Code Without Integrity Check CWE

Impacts

  • CAPEC-185 Malicious Software Download