PT-2018-11807 · Zoho · Zoho Manageengine Desktop Central

Abdullah Aljaber

·

Published

2018-09-12

·

Updated

2021-04-21

·

CVE-2018-13411

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Zoho ManageEngine Desktop Central versions prior to 10.0.282 Zoho ManageEngine Desktop Central agent versions prior to 10.0.470
Description A security issue was found in Zoho ManageEngine Desktop Central, where a clickable company logo in a window running as SYSTEM can be exploited to escalate privileges.
Recommendations For versions prior to 10.0.282, update to version 10.0.282 or later to resolve the issue. For cloud agent versions prior to 10.0.470, update to agent version 10.0.470 or later to fix the issue.

Exploit

Fix

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-13411

Affected Products

Zoho Manageengine Desktop Central