Remote code execution vulnerability in Zoho ManageEngine Desktop Central

Remote code execution vulnerability in Zoho ManageEngine Desktop Central

Software Affected
• Zoho ManageEngine Desktop Central prior to 10.0.474

Overview
A vulnerability has been reported in Zoho ManageEngine Desktop Central, which could allow an unauthenticated remote attacker to execute arbitrary code on a targeted system.

Description
This vulnerability exists in Zoho ManageEngine Desktop Central due to improper input validation in the FileStorage class. An unauthenticated remote attacker could exploit this vulnerability by uploading a malicious file containing a serialized payload onto an affected system and then make a subsequent request for the uploaded file to trigger untrusted deserialization.
Successful exploitation of this vulnerability may allow the attacker to gain root-level access and execute arbitrary code on the targeted system.

Comments

Post a Comment

Popular posts from this blog

CAREER TECHNOLOGY CYBER SECURITY INDIA PVT LTD.

Cyber Security Audits

Some Dark web Links