Zoho ManageEngine ADManager Plus 6.6.5, ADSelfService Plus 5.7, and DesktopCentral 10.0.380 have Insecure Permissions, leading to Privilege Escalation from low level privileges to System.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Link | Tags |
---|---|
https://www.criticalstart.com/2019/07/manageengine-privilege-escalation/ | third party advisory exploit |
http://www.securityfocus.com/bid/109298 | vdb entry third party advisory |