ZeroHour

CVE-2020-10189

KEV PoC ×3large

Unauthenticated RCE in Zoho ManageEngine Desktop Central

CISA: Zoho ManageEngine Desktop Central File Upload Vulnerability

CVSS 3.1
9.8 critical
EPSS
100%p100
Published
()
KEV added
AI analysis

Zoho ManageEngine Desktop Central contains a file upload vulnerability (CWE-502, deserialization of untrusted data) that can be exploited without authentication. A remote attacker sends crafted upload requests to the affected application, which accepts and processes the uploaded content without any credentials, resulting in execution of attacker-controlled code. Successful exploitation yields remote code execution on the server hosting Desktop Central, giving the attacker a foothold on an endpoint-management system that typically has broad reach into a corporate network. Any organization running the affected Zoho ManageEngine product is exposed, and exploitability does not depend on user interaction or credentials. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), indicating known exploitation in the wild, and EPSS assigns a 99.9% probability of exploitation within 30 days; specific exploited versions are not stated in the available data.

What to do: Apply updates per Zoho/ManageEngine vendor instructions immediately, as the CISA KEV required action specifies. Restrict internet exposure of the Desktop Central server and audit it for signs of compromise (unexpected processes, webshells, outbound connections) since unauthenticated RCE has been exploited in the wild. Check that any exposed instances are patched before treating network access as safe.

Affected
Zoho ManageEngine Desktop Central (CISA: "Zoho ManageEngine")
Estimated exposure
largetens of thousands of internet-exposed Desktop Central servers (order of magnitude 10k-100k) — Public internet-wide scans have repeatedly found tens of thousands of exposed ManageEngine Desktop Central instances, and the product is a widely deployed enterprise endpoint-management platform whose managed-endpoint fleets are far larger…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImage in the FileStorage class. This is related to the CewolfServlet and MDMLogUploaderServlet servlets.

CISA Known Exploited Vulnerability
Affected
Zoho ManageEngine
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
zohocorp
Products
manageengine desktop central
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news