VulnerabilityModified
CVE-2014-7862
The DCPluginServelet servlet in ManageEngine Desktop Central and Desktop Central MSP before build 90109 allows remote attackers to create administrator accounts via an addPlugInUser action.
CRITICAL 9.8EPSS 81.0%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 81.0%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
The DCPluginServelet servlet in ManageEngine Desktop Central and Desktop Central MSP before build 90109 allows remote attackers to create administrator accounts via an addPlugInUser action.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 81.05% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- zohocorp/desktop central
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/129769/Desktop-Central-Add-Administrator.htmlIssue Tracking, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2015/Jan/2Issue Tracking, Mailing List, Third Party Advisory
- http://www.securityfocus.com/archive/1/534356/100/0/threaded
- http://www.securityfocus.com/bid/71849Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/99595Issue Tracking, Third Party Advisory, VDB Entry
- https://github.com/pedrib/PoC/blob/master/advisories/ManageEngine/me_dc9_admin.txtThird Party Advisory
- https://www.manageengine.com/products/desktop-central/cve20147862-unauthorized-account-creation.htmlThird Party Advisory
- https://www.rapid7.com/db/modules/auxiliary/admin/http/manage_engine_dc_create_adminExploit, Third Party Advisory
- http://packetstormsecurity.com/files/129769/Desktop-Central-Add-Administrator.htmlIssue Tracking, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2015/Jan/2Issue Tracking, Mailing List, Third Party Advisory
- http://www.securityfocus.com/archive/1/534356/100/0/threaded
- http://www.securityfocus.com/bid/71849Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/99595Issue Tracking, Third Party Advisory, VDB Entry
- https://github.com/pedrib/PoC/blob/master/advisories/ManageEngine/me_dc9_admin.txtThird Party Advisory
- https://www.manageengine.com/products/desktop-central/cve20147862-unauthorized-account-creation.htmlThird Party Advisory
- https://www.rapid7.com/db/modules/auxiliary/admin/http/manage_engine_dc_create_adminExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.