SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2021-44515

Zoho Desktop Central Authentication Bypass Vulnerability

KEVCRITICAL 9.8EPSS 99.9%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 24 December 2021). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

Zoho ManageEngine Desktop Central is vulnerable to authentication bypass, leading to remote code execution on the server, as exploited in the wild in December 2021. For Enterprise builds 10.1.2127.17 and earlier, upgrade to 10.1.2127.18. For Enterprise builds 10.1.2128.0 through 10.1.2137.2, upgrade to 10.1.2137.3. For MSP builds 10.1.2127.17 and earlier, upgrade to 10.1.2127.18. For MSP builds 10.1.2128.0 through 10.1.2137.2, upgrade to 10.1.2137.3.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
99.87% probability · 100th percentile
CISA KEV
Listed 10 December 2021 · due 24 December 2021
Affected
zohocorp/manageengine desktop central
Source
cve@mitre.org

CISA notes

Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2021-44515

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.