ZeroHour

CVE-2022-28810

KEV PoC ×3large

Authenticated Command Injection RCE in ManageEngine ADSelfService Plus

CISA: Zoho ManageEngine ADSelfService Plus Remote Code Execution Vulnerability

CVSS 3.1
6.8 medium
EPSS
71%p99
Published
()
KEV added
AI analysis

CVE-2022-28810 is an operating system command injection flaw (CWE-78) in the policy custom script feature of Zoho ManageEngine ADSelfService Plus, compounded by use of a default administrator password (CWE-798). A remote authenticated administrator can run arbitrary OS commands through a crafted custom script, and, because the password field is unsanitized, a partially authenticated attacker may also inject commands through it. Successful exploitation executes commands as SYSTEM, giving the attacker full control of the hosting Windows server. Organizations running ADSelfService Plus builds before 6122 are affected. The flaw has public proof-of-concept code and a Metasploit module, a 71% EPSS score, and was added to CISA's Known Exploited Vulnerabilities Catalog on 2023-03-07, indicating active in-the-wild exploitation.

What to do: Upgrade ManageEngine ADSelfService Plus to build 6122 or later per the vendor's instructions; this is a required action for federal agencies under the CISA KEV listing. Until patched, restrict internet exposure of the console and self-service endpoints, replace default administrator credentials, and review configured policy custom scripts and SYSTEM-context process logs for signs of command injection. Given the product's history of APT targeting, hunt for follow-on activity on any host that ran ADSelfService Plus unpatched.

Affected
Zoho (zohocorp) ManageEngine ADSelfService Plusall builds before 6122
Estimated exposure
largetens of thousands of enterprise deployments, several thousand of them internet-exposed; plausibly 100,000+ end users in aggregate — ADSelfService Plus is a widely deployed on-prem Active Directory self-service product typically installed at the enterprise perimeter, and public internet scans have historically shown thousands of exposed instances, each serving an entire…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary operating OS commands as SYSTEM via the policy custom script feature. Due to the use of a default administrator password, attackers may be able to abuse this functionality with minimal effort. Additionally, a remote and partially authenticated attacker may be able to inject arbitrary commands into the custom script due to an unsanitized password field.

CISA Known Exploited Vulnerability
Affected
Zoho ManageEngine
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
zohocorp
Products
manageengine adselfservice plus
Weakness
CWE-78, CWE-798
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H

In the news