PT-2025-39370 · Zohocorp · Manageengine Endpoint Central

Published

2025-04-24

·

Updated

2025-09-25

·

CVE-2025-5494

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ZohoCorp ManageEngine Endpoint Central versions through 11.4.2500.25 ZohoCorp ManageEngine Endpoint Central versions through 11.4.2508.13
Description An improper privilege management issue exists in the agent setup of ZohoCorp ManageEngine Endpoint Central. The issue relates to how privileges are handled during the agent installation process.
Recommendations Update ZohoCorp ManageEngine Endpoint Central to a version later than 11.4.2500.25. Update ZohoCorp ManageEngine Endpoint Central to a version later than 11.4.2508.13.

Fix

LPE

Improper Privilege Management

Weakness Enumeration

Related Identifiers

BDU:2025-12731
CVE-2025-5494

Affected Products

Manageengine Endpoint Central