PT-2021-12847 · Zoho · Zoho Manageengine Desktop Central
Andrea Ghelli
·
Published
2021-03-18
·
Updated
2021-03-25
·
CVE-2020-9367
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Zoho ManageEngine Desktop Central MSP version 10.0.486
Description:
The issue is related to DLL Hijacking, where
dcinventory.exe and dcconfig.exe attempt to load CSUNSAPI.dll without providing a complete path. This is problematic because the DLL is missing from the installation, allowing for potential DLL hijacking and code injection, which could lead to an escalation of privilege to NT AUTHORITYSYSTEM.Recommendations:
For version 10.0.486, consider disabling the
dcinventory.exe and dcconfig.exe executables as a temporary workaround until a patch is available. Restrict access to these executables to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Uncontrolled Search Path Element
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zoho Manageengine Desktop Central