PT-2018-11528 · Zoho · Zoho Manageengine Desktop Central

Xiaotian.Wang

·

Published

2018-06-29

·

Updated

2018-08-20

·

CVE-2018-12999

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Zoho ManageEngine Desktop Central version 10.0.255
Description The issue allows attackers to delete certain files on the web server without login by sending a specially crafted request to the server. This is achieved by including a computerName=../ substring in the request to the "/agenttrayicon" API endpoint.
Recommendations For Zoho ManageEngine Desktop Central version 10.0.255, consider restricting access to the AgentTrayIconServlet to prevent unauthorized file deletion until a patch is available. As a temporary workaround, avoid using the computerName variable in the affected API endpoint.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-12999

Affected Products

Zoho Manageengine Desktop Central