Remote code execution vulnerability in Zoho ManageEngine Desktop Central
Remote code execution vulnerability in Zoho ManageEngine Desktop Central
Software Affected
• Zoho ManageEngine Desktop Central prior to 10.0.474
Overview
A vulnerability has been reported in Zoho ManageEngine Desktop Central, which could allow an unauthenticated remote attacker to execute arbitrary code on a targeted system.
Description
This vulnerability exists in Zoho ManageEngine Desktop Central due to improper input validation in the FileStorage class. An unauthenticated remote attacker could exploit this vulnerability by uploading a malicious file containing a serialized payload onto an affected system and then make a subsequent request for the uploaded file to trigger untrusted deserialization.
Successful exploitation of this vulnerability may allow the attacker to gain root-level access and execute arbitrary code on the targeted system.
Software Affected
• Zoho ManageEngine Desktop Central prior to 10.0.474
Overview
A vulnerability has been reported in Zoho ManageEngine Desktop Central, which could allow an unauthenticated remote attacker to execute arbitrary code on a targeted system.
Description
This vulnerability exists in Zoho ManageEngine Desktop Central due to improper input validation in the FileStorage class. An unauthenticated remote attacker could exploit this vulnerability by uploading a malicious file containing a serialized payload onto an affected system and then make a subsequent request for the uploaded file to trigger untrusted deserialization.
Successful exploitation of this vulnerability may allow the attacker to gain root-level access and execute arbitrary code on the targeted system.
Thanks for sharing such a nice Post. I must suggest your readers to Visit Cyber Security Training
ReplyDelete