Version 4.3.0
Original release notes
- Accessibility improvements.
- Design improvements and minor bug fixes in installer.
- Corrects an issue which caused occasional black or frozen screens during Duo login.
- Adds an optional registry setting ParseUsernameAndDomain which overrides Duo user/domain determination logic by parsing the username provided by the user. Refer to Why might an incorrect username get sent to Duo from a machine joined to Entra ID? for more information.
- Addresses a security vulnerability where trusted sessions persisted after a reboot (CVE-2024-20301; Cisco Security Advisory).
- Addresses a security vulnerability where the Duo secret key value was logged in plaintext during an application upgrade (CVE-2024-20292; Cisco Security Advisory).
- We recommend you migrate to a new instance of the application to preserve the integrity of the application credentials on your client systems. Refer to Duo KB Article 8760 for step-by-step instructions. Refer to the Duo KB article What are Duo application credentials and how should I protect them? for more information.
- Corrects an issue where the installer did not secure the Duo registry key so integration credentials could be read by unprivileged users until the registry key was secured by first launch of the application.
- The exe installer now defaults to "fail closed" for the Bypass Duo authentication when offline (FailOpen) setting and overrides the previous fail mode selection. The msi installer will default to "fail closed" for net new installations, but upgrades will preserve the previous fail mode selection.
- Automatic push (AUTOPUSH) now enabled by default for silent installs.