UK’s NHS Digital agency is warning organizations to apply new security updates for a remote code execution vulnerability in the Windows client for the Okta Advanced Server Access authentication management platform. Remote code execution attacks can lead to complete system control, perform silent data exfiltration, lateral network movement, and initial access to corporate networks. No technical details of the flaw’s exploitation have been disclosed to the public. The vendor hasn’t provided any mitigations or workarounds so the remediation advice is limited to updating to the latest client available from Okta.”]

