PT-2020-10038 · Microsoft+1 · System Center Configuration Manager+1

Published

2020-03-23

·

Updated

2023-02-03

·

CVE-2019-19034

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zoho ManageEngine Asset Explorer version 6.5
Description The issue arises from the lack of validation of the System Center Configuration Manager (SCCM) database username when dynamically generating a command to schedule scans for SCCM. This allows an attacker to execute arbitrary commands on the AssetExplorer Server with NT AUTHORITY/SYSTEM privileges.
Recommendations For Zoho ManageEngine Asset Explorer version 6.5, consider disabling the dynamic command generation for SCCM scans until a patch is available to prevent arbitrary command execution. Restrict access to the AssetExplorer Server to minimize the risk of exploitation.

Exploit

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2019-19034

Affected Products

System Center Configuration Manager
Zoho Manageengine Assetexplorer