Zoho ManageEngine ADSelfService Plus Remote Command Execution Vulnerability
Vulnerability allows for remote command execution when performing a password change or reset
Summary
Vulnerability allows for remote command execution when performing a password change or reset
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
Zoho have reported a vulnerability in ManageEngine ADSelfService Plus that could lead to remote command execution. When performing a password change or reset, an authenticated attacker could exploit this vulnerability by entering a CMD command in the password field and have it run remotely on the ADSelfService Plus server. This vulnerability applies when administrators have enabled custom scripts for password sync with required providers and set the passwords to be sent as arguments during the sync process.
CISA adds CVE-2022-28810 to Known Exploited Vulnerability Catalog
CISA has added the vulnerability CVE-2022-28810 to the Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation.
Remediation advice
Affected organisations are encouraged to view the relevant Zoho ManageEngine Security Advisory and follow the remediation advice there.
Definitive source of threat updates
Last edited: 9 March 2023 11:41 am