ZeroHour

CVE-2021-44077

KEV PoC large

Unauthenticated RCE in Zoho ManageEngine ServiceDesk Plus and SupportCenter Plus

CISA: Zoho ManageEngine ServiceDesk Plus Remote Code Execution Vulnerability

CVSS 3.1
9.8 critical
EPSS
93%p100
Published
()
KEV added
AI analysis

CVE-2021-44077 is a critical (CVSS 9.8) unauthenticated remote code execution flaw in Zoho ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP, and SupportCenter Plus, rooted in missing authentication (CWE-306) on /RestAPI servlet URLs, specifically the ImportTechnicians action in the Struts configuration. A remote attacker can trigger it by sending crafted unauthenticated requests to the RestAPI endpoints, requiring no credentials or user interaction. Successful exploitation yields arbitrary code execution in the context of the application, giving attackers full control of the help desk server as a foothold for further network compromise. Any organization running affected versions before ServiceDesk Plus 11306, ServiceDesk Plus MSP 10530, or SupportCenter Plus 11014 is affected, particularly where the console is internet-facing. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2021-12-01, carries a 93.3% EPSS probability of near-term exploitation, and headlines point to active APT campaigns and mass exploitation against ManageEngine ServiceDesk deployments.

What to do: Upgrade to the fixed releases: ServiceDesk Plus 11306 or later, ServiceDesk Plus MSP 10530 or later, and SupportCenter Plus 11014 or later, per vendor instructions (CISA KEV requires this action). Until patched, restrict or firewall internet access to /RestAPI endpoints, and review access logs for unauthenticated requests to the ImportTechnicians action along with unexpected processes, files, or webshells on the server. Given the 93.3% EPSS score, active APT exploitation, and concurrent zero-day activity against other ManageEngine products, treat exposed instances as potentially compromised and hunt for post-exploitation activity.

Affected
zohocorp ManageEngine ServiceDesk Plusall versions before 11306
zohocorp ManageEngine ServiceDesk Plus MSPall versions before 10530
zohocorp ManageEngine SupportCenter Plusall versions before 11014
Estimated exposure
largetens of thousands of on-prem help desk deployments worldwide, with thousands of instances directly internet-exposed (estimate) — ServiceDesk Plus is among the most widely deployed on-prem ITSM/help desk products, and public internet scans have shown thousands of exposed instances, with total deployments (including internal-only installs) plausibly in the tens of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution. This is related to /RestAPI URLs in a servlet, and ImportTechnicians in the Struts configuration.

CISA Known Exploited Vulnerability
Affected
Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
zohocorp
Products
manageengine servicedesk plus, manageengine servicedesk plus msp, manageengine supportcenter plus
Weakness
CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news