


Perceptive Security
SOC/SIEM Consultancy

IDExpert Windows Logon Agent developed by Changing has a Remote Code Execution vulnerability, allowing unauthenticated remote attackers to force the system to d…
Published:
1 March 2026 at 23:00:00
Alert date:
2 March 2026 at 08:01:55
Source:
nvd.nist.gov
Operating Systems, Identity & Access
IDExpert Windows Logon Agent developed by Changing contains a critical Remote Code Execution vulnerability (CVE-2026-3000). The vulnerability allows unauthenticated remote attackers to force the system to download arbitrary DLL files from remote sources and execute them. This represents a severe security flaw that could enable complete system compromise without requiring authentication. The vulnerability affects Windows authentication systems and could potentially be exploited for widespread attacks against enterprise environments using the IDExpert solution.
Technical details
Mitigation steps:
Affected products:
IDExpert Windows Logon Agent
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-3000
https://www.changingtec.com/news_detail.jsp?item_id=348
https://www.twcert.org.tw/en/cp-139-10741-daed4-2.html
https://www.twcert.org.tw/tw/cp-132-10740-b2eb2-1.html
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
