PT-2020-2203 · Zoho · Zoho Manageengine Desktop Central

Steven Seeley

·

Published

2020-03-06

·

Updated

2026-04-06

·

CVE-2020-10189

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Zoho ManageEngine Desktop Central versions prior to 10.0.474
Description The issue is related to the deserialization of untrusted data in the getChartImage method of the FileStorage class, which is associated with the CewolfServlet and MDMLogUploaderServlet servlets. This allows for remote code execution.
Recommendations For versions prior to 10.0.474, update to version 10.0.474 or later to resolve the issue. As a temporary workaround, consider restricting access to the CewolfServlet and MDMLogUploaderServlet servlets until a patch is applied. Additionally, avoid using the getChartImage method in the FileStorage class until the issue is resolved.

Exploit

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

BDU:2020-02110
CVE-2020-10189

Affected Products

Zoho Manageengine Desktop Central