PT-2022-7140 · Zoho · Zoho Manageengine Device Control Plus

Published

2022-12-19

·

Updated

2024-08-03

·

CVE-2022-47577

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zoho ManageEngine Device Control Plus version 10.1.2228.15
Description An issue in the endpoint protection agent of Zoho ManageEngine Device Control Plus allows bypassing USB restrictions by using a virtual machine (VM), enabling file exchange outside the system without leaving a record in the Windows event audit trail. This can be done by any user, even without admin rights. The issue is related to insufficient access control.
Recommendations For Zoho ManageEngine Device Control Plus version 10.1.2228.15, consider disabling the creation of virtual machines (VMs) by non-admin users as a temporary workaround to minimize the risk of exploitation. Restrict access to VM creation to only authorized personnel until a fix is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Access Control

Incorrect Privilege Assignment

Weakness Enumeration

Related Identifiers

BDU:2023-07848
CVE-2022-47577

Affected Products

Zoho Manageengine Device Control Plus