CVE-2022-48362
Zoho ManageEngine Desktop Central and Desktop Central MSP before 10.1.2137.2 allow directory traversal via computerName to AgentLogUploadServlet.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (8.67%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Zoho ManageEngine Desktop Central and Desktop Central MSP before 10.1.2137.2 allow directory traversal via computerName to AgentLogUploadServlet. A remote, authenticated attacker could upload arbitrary code that would be executed when Desktop Central is restarted. (The attacker could authenticate by exploiting CVE-2021-44515.)
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 8.67% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- zohocorp/manageengine desktop central
- Source
- cve@mitre.org
References
- https://srcincite.io/blog/2022/01/20/zohowned-a-critical-authentication-bypass-on-zoho-manageengine-desktop-central.htmlExploit, Vendor Advisory
- https://www.manageengine.com/products/desktop-central/cve-2022-48362.html
- https://srcincite.io/blog/2022/01/20/zohowned-a-critical-authentication-bypass-on-zoho-manageengine-desktop-central.htmlExploit, Vendor Advisory
- https://www.manageengine.com/products/desktop-central/cve-2022-48362.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.