PT-2020-2203 · Zoho · Zoho Manageengine Desktop Central
Steven Seeley
·
Published
2020-03-06
·
Updated
2026-04-06
·
CVE-2020-10189
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Zoho ManageEngine Desktop Central versions prior to 10.0.474
Description
The issue is related to the deserialization of untrusted data in the
getChartImage method of the FileStorage class, which is associated with the CewolfServlet and MDMLogUploaderServlet servlets. This allows for remote code execution.Recommendations
For versions prior to 10.0.474, update to version 10.0.474 or later to resolve the issue. As a temporary workaround, consider restricting access to the
CewolfServlet and MDMLogUploaderServlet servlets until a patch is applied. Additionally, avoid using the getChartImage method in the FileStorage class until the issue is resolved.Exploit
Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zoho Manageengine Desktop Central