Zoho · Zoho Manageengine Opmanager · CVE-2019-17421
**Name of the Vulnerable Software and Affected Versions**
Zoho ManageEngine OpManager version 12.4.072
Zoho ManageEngine Firewall Analyzer version 12.4.072
**Description**
The issue arises from incorrect file permissions on the packaged Nipper executable file, allowing local users to elevate privileges to root by overwriting this file with a malicious payload.
**Recommendations**
For Zoho ManageEngine OpManager version 12.4.072, update the file permissions of the Nipper executable to prevent local users from overwriting it.
For Zoho ManageEngine Firewall Analyzer version 12.4.072, update the file permissions of the Nipper executable to prevent local users from overwriting it.