PT-2018-11528 · Zoho · Zoho Manageengine Desktop Central
Xiaotian.Wang
·
Published
2018-06-29
·
Updated
2018-08-20
·
CVE-2018-12999
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Zoho ManageEngine Desktop Central version 10.0.255
Description
The issue allows attackers to delete certain files on the web server without login by sending a specially crafted request to the server. This is achieved by including a
computerName=../ substring in the request to the "/agenttrayicon" API endpoint.Recommendations
For Zoho ManageEngine Desktop Central version 10.0.255, consider restricting access to the AgentTrayIconServlet to prevent unauthorized file deletion until a patch is available. As a temporary workaround, avoid using the
computerName variable in the affected API endpoint.Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zoho Manageengine Desktop Central