CVE-2022-28810
KEV PoC ×3largeAuthenticated Command Injection RCE in ManageEngine ADSelfService Plus
CISA: Zoho ManageEngine ADSelfService Plus Remote Code Execution Vulnerability
CVE-2022-28810 is an operating system command injection flaw (CWE-78) in the policy custom script feature of Zoho ManageEngine ADSelfService Plus, compounded by use of a default administrator password (CWE-798). A remote authenticated administrator can run arbitrary OS commands through a crafted custom script, and, because the password field is unsanitized, a partially authenticated attacker may also inject commands through it. Successful exploitation executes commands as SYSTEM, giving the attacker full control of the hosting Windows server. Organizations running ADSelfService Plus builds before 6122 are affected. The flaw has public proof-of-concept code and a Metasploit module, a 71% EPSS score, and was added to CISA's Known Exploited Vulnerabilities Catalog on 2023-03-07, indicating active in-the-wild exploitation.
What to do: Upgrade ManageEngine ADSelfService Plus to build 6122 or later per the vendor's instructions; this is a required action for federal agencies under the CISA KEV listing. Until patched, restrict internet exposure of the console and self-service endpoints, replace default administrator credentials, and review configured policy custom scripts and SYSTEM-context process logs for signs of command injection. Given the product's history of APT targeting, hunt for follow-on activity on any host that ran ADSelfService Plus unpatched.
| Zoho (zohocorp) ManageEngine ADSelfService Plus | all builds before 6122 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary operating OS commands as SYSTEM via the policy custom script feature. Due to the use of a default administrator password, attackers may be able to abuse this functionality with minimal effort. Additionally, a remote and partially authenticated attacker may be able to inject arbitrary commands into the custom script due to an unsanitized password field.
- Affected
- Zoho ManageEngine
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- zohocorp
- Products
- manageengine adselfservice plus
- Weakness
- CWE-78, CWE-798
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H