ZeroHour

CVE-2022-35405

KEV PoC large

Deserialization RCE in ManageEngine Password Manager Pro, PAM360, and Access Manager Plus

CISA: Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability

CVSS 3.1
9.8 critical
EPSS
100%p100
Published
()
KEV added
AI analysis

Zoho ManageEngine PAM360, Password Manager Pro, and Access Manager Plus contain a flaw classified as deserialization of untrusted data (CWE-502) that allows an unauthenticated attacker to achieve remote code execution by sending crafted serialized data to the server. Because no authentication or user interaction is required, any client that can reach the product's network service can submit input that the application deserializes and executes. A successful attacker gains code execution with the privileges of the product's service, typically yielding control of the server and, critically, access to the vault of privileged credentials these products store, enabling lateral movement and ransomware campaigns. Any organization running one of these three ManageEngine password and access management products is in scope. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-09-22, and EPSS estimates a 99.9% probability of exploitation within 30 days.

What to do: Apply the updates Zoho released for all three products immediately, as CISA's required action specifies applying vendor updates: inventory whether you run Password Manager Pro, PAM360, or Access Manager Plus, and upgrade to the fixed builds named in each product's advisory. Until patched, restrict network access to the products' HTTPS management service (e.g., Password Manager Pro's default service port 7272) to trusted administrative networks only. After patching, hunt for signs of compromise such as unexpected processes, new accounts, or use of vaulted credentials, since the KEV listing implies exploitation and ransomware association is listed as unknown.

Affected
Zoho ManageEngine Password Manager Pro
Zoho ManageEngine PAM360
Zoho ManageEngine Access Manager Plus
Estimated exposure
largetens of thousands of enterprise deployments across the three products, including several thousand internet-exposed instances visible in public scans,… — These are enterprise-wide privileged credential vaults marketed to large organizations (ManageEngine's overall install base spans hundreds of thousands of organizations) and public internet scans show thousands of exposed instances, so I…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution. (This also affects ManageEngine Access Manager Plus before 4303 with authentication.)

CISA Known Exploited Vulnerability
Affected
Zoho ManageEngine
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
zohocorp
Products
manageengine access manager plus, manageengine pam360, manageengine password manager pro
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news