Skip to main content

Zoho ManageEngine ADSelfService Plus Remote Command Execution Vulnerability

Vulnerability allows for remote command execution when performing a password change or reset

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Vulnerability allows for remote command execution when performing a password change or reset


Affected platforms

The following platforms are known to be affected:

Threat details

Introduction

Zoho have reported a vulnerability in ManageEngine ADSelfService Plus that could lead to remote command execution. When performing a password change or reset, an authenticated attacker could exploit this vulnerability by entering a CMD command in the password field and have it run remotely on the ADSelfService Plus server. This vulnerability applies when administrators have enabled custom scripts for password sync with required providers and set the passwords to be sent as arguments during the sync process. 

CISA adds CVE-2022-28810 to Known Exploited Vulnerability Catalog

CISA has added the vulnerability CVE-2022-28810 to the Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation.


Remediation advice

Affected organisations are encouraged to view the relevant Zoho ManageEngine Security Advisory and follow the remediation advice there. 



Last edited: 9 March 2023 11:41 am