Unrated severityNVD Advisory· Published Mar 2, 2026· Updated Mar 2, 2026
Changing|IDExpert Windows Logon Agent - Remote Code Execution
CVE-2026-2999
Description
IDExpert Windows Logon Agent developed by Changing has a Remote Code Execution vulnerability, allowing unauthenticated remote attackers to force the system to download arbitrary executable files from a remote source and execute them.
Affected products
1- Range: 2.7.3.230719
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.changingtec.com/news_detail.jspmitrevendor-advisory
- www.twcert.org.tw/en/cp-139-10741-daed4-2.htmlmitrethird-party-advisory
- www.twcert.org.tw/tw/cp-132-10740-b2eb2-1.htmlmitrethird-party-advisory
News mentions
0No linked articles in our index yet.