CVE-2026-2999
Published: 02 March 2026
Description
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
Security Summary
CVE-2026-2999 is a Remote Code Execution vulnerability affecting the IDExpert Windows Logon Agent developed by Changing. Published on 2026-03-02T07:16:22.743, it carries a CVSS v3.1 base score of 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) and maps to CWE-494. The flaw enables unauthenticated remote attackers to force affected systems to download arbitrary executable files from a remote source and execute them.
Unauthenticated attackers can exploit this vulnerability remotely over the network with low attack complexity, requiring no privileges or user interaction. Successful exploitation grants high-impact access to confidentiality, integrity, and availability, allowing arbitrary code execution on the target system.
Mitigation details are outlined in advisories from the vendor at https://www.changingtec.com/news_detail.jsp?item_id=348 and from TWCERT at https://www.twcert.org.tw/en/cp-139-10741-daed4-2.html and https://www.twcert.org.tw/tw/cp-132-10740-b2eb2-1.html.
Details
- CWE(s)
Affected Products
MITRE ATT&CK Enterprise Techniques
Why these techniques?
Unauthenticated remote code execution vulnerability in a network-exposed Windows service (Logon Agent) enables exploitation of a public-facing application to download and execute arbitrary code.