PT-2021-12847 · Zoho · Zoho Manageengine Desktop Central

Andrea Ghelli

·

Published

2021-03-18

·

Updated

2021-03-25

·

CVE-2020-9367

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Zoho ManageEngine Desktop Central MSP version 10.0.486
Description: The issue is related to DLL Hijacking, where dcinventory.exe and dcconfig.exe attempt to load CSUNSAPI.dll without providing a complete path. This is problematic because the DLL is missing from the installation, allowing for potential DLL hijacking and code injection, which could lead to an escalation of privilege to NT AUTHORITYSYSTEM.
Recommendations: For version 10.0.486, consider disabling the dcinventory.exe and dcconfig.exe executables as a temporary workaround until a patch is available. Restrict access to these executables to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Uncontrolled Search Path Element

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-9367

Affected Products

Zoho Manageengine Desktop Central