IDExpert Windows Logon Agent developed by Changing has a Remote Code Execution vulnerability, allowing unauthenticated remote attackers to force the system to download arbitrary DLL files from a remote source and execute them.

Project Subscriptions

Vendors Products
Changing Subscribe
Idexpert Windows Logon Agent Subscribe
Changingtec Subscribe
Idexpert Subscribe
Advisories

No advisories yet.

Fixes

Solution

Contact the vendor to patch or download the patch from the official website. Link: https://www.changingtec.com/news_detail.jsp?item_id=348


Workaround

No workaround given by the vendor.

History

Mon, 09 Mar 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Changingtec
Changingtec idexpert
CPEs cpe:2.3:a:changingtec:idexpert:*:*:*:*:*:windows:*:*
Vendors & Products Changingtec
Changingtec idexpert

Wed, 04 Mar 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Changing
Changing idexpert Windows Logon Agent
Vendors & Products Changing
Changing idexpert Windows Logon Agent

Mon, 02 Mar 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 02 Mar 2026 06:30:00 +0000

Type Values Removed Values Added
Description IDExpert Windows Logon Agent developed by Changing has a Remote Code Execution vulnerability, allowing unauthenticated remote attackers to force the system to download arbitrary DLL files from a remote source and execute them.
Title Changing|IDExpert Windows Logon Agent - Remote Code Execution
Weaknesses CWE-494
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2026-03-02T14:08:22.120Z

Reserved: 2026-02-23T01:38:31.326Z

Link: CVE-2026-3000

cve-icon Vulnrichment

Updated: 2026-03-02T14:08:13.909Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-02T07:16:23.013

Modified: 2026-03-09T14:21:34.527

Link: CVE-2026-3000

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-03T08:45:59Z

Weaknesses