CVE-2022-28810
Zoho ManageEngine ADSelfService Plus Remote Code Execution Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 28 March 2023). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary operating OS commands as SYSTEM via the policy custom script feature. Due to the use of a default administrator password, attackers may be able to abuse this functionality with minimal effort. Additionally, a remote and partially authenticated attacker may be able to inject arbitrary commands into the custom script due to an unsanitized password field.
- CVSS 3.1
- 6.8 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 70.97% probability · 99th percentile
- CISA KEV
- Listed 7 March 2023 · due 28 March 2023
- Weakness
- CWE-78, CWE-798
- Affected
- zohocorp/manageengine adselfservice plus
- Source
- cve@mitre.org
CISA notes
Apply updates per vendor instructions. https://www.manageengine.com/products/self-service-password/advisory/CVE-2022-28810.html; https://nvd.nist.gov/vuln/detail/CVE-2022-28810
References
- http://packetstormsecurity.com/files/166816/ManageEngine-ADSelfService-Plus-Custom-Script-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://github.com/rapid7/metasploit-framework/pull/16475Exploit, Patch, Third Party Advisory
- https://www.manageengine.com/products/self-service-password/kb/cve-2022-28810.htmlPatch, Vendor Advisory
- https://www.rapid7.com/blog/post/2022/04/14/cve-2022-28810-manageengine-adselfservice-plus-authenticated-command-execution-fixed/Exploit, Patch, Technical Description, Third Party Advisory
- http://packetstormsecurity.com/files/166816/ManageEngine-ADSelfService-Plus-Custom-Script-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://github.com/rapid7/metasploit-framework/pull/16475Exploit, Patch, Third Party Advisory
- https://www.manageengine.com/products/self-service-password/kb/cve-2022-28810.htmlPatch, Vendor Advisory
- https://www.rapid7.com/blog/post/2022/04/14/cve-2022-28810-manageengine-adselfservice-plus-authenticated-command-execution-fixed/Exploit, Patch, Technical Description, Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-28810US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.