ZeroHour
The Recordpublished ()ingested

Zoho warns of new zero

criticalExploit / PoC exploited in the wildimportance 60CVE-2021-44515CVE-2021-40539CVE-2021-44077

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-40539
Unauthenticated RCE via REST API auth bypass in Zoho ManageEngine ADSelfService Plus

CVE-2021-40539 is a critical (CVSS 9.8) authentication bypass in the REST API of Zoho ManageEngine ADSelfService Plus, caused by use of an incorrectly resolved name or reference (CWE-706). An unauthenticated, network-adjacent or internet-reachable attacker sends specially crafted requests to the product's REST API, bypassing authentication, and can chain the bypass to full remote code execution with no privileges or user interaction required. Successful exploitation yields complete compromise of the self-service portal server (high impact to confidentiality, integrity and availability); public reporting and vendor notes document attackers dropping malicious code and web shells onto vulnerable servers. Any organization running ManageEngine ADSelfService Plus build 6113 or earlier is affected, which typically means enterprise Microsoft Active Directory environments running this widely deployed self-service password/SSO portal. Exploitation is confirmed in the wild: the flaw was added to CISA KEV on 2021-11-03 with known ransomware use, EPSS puts the 30-day exploitation probability at 99% (100th percentile), Microsoft warned that Chinese threat actors were actively exploiting it, a public proof-of-concept is available, and it ranked among CISA's most routinely exploited vulnerabilities.

Do: Immediately upgrade ManageEngine ADSelfService Plus to a fixed build newer than 6113 per the vendor's update instructions, as required by CISA. Because exploitation predates patching and the flaw has been used to drop malicious code, check ADSelfService Plus servers for web shells, unexpected scheduled tasks, and unexplained accounts/processes, and hunt for indicators from the published analyses. Where possible, restrict internet exposure of the ADSelfService Plus REST API while patching, prioritized for externally reachable instances.

9.899% KEV ransomware PoC
  • Zoho (zohocorp) ManageEngine ADSelfService Plus 6113 and prior
largetens of thousands of enterprise server installations (unknown precise count)
CVE-2021-44077
Unauthenticated RCE in Zoho ManageEngine ServiceDesk Plus and SupportCenter Plus

CVE-2021-44077 is a critical (CVSS 9.8) unauthenticated remote code execution flaw in Zoho ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP, and SupportCenter Plus, rooted in missing authentication (CWE-306) on /RestAPI servlet URLs, specifically the ImportTechnicians action in the Struts configuration. A remote attacker can trigger it by sending crafted unauthenticated requests to the RestAPI endpoints, requiring no credentials or user interaction. Successful exploitation yields arbitrary code execution in the context of the application, giving attackers full control of the help desk server as a foothold for further network compromise. Any organization running affected versions before ServiceDesk Plus 11306, ServiceDesk Plus MSP 10530, or SupportCenter Plus 11014 is affected, particularly where the console is internet-facing. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2021-12-01, carries a 93.3% EPSS probability of near-term exploitation, and headlines point to active APT campaigns and mass exploitation against ManageEngine ServiceDesk deployments.

Do: Upgrade to the fixed releases: ServiceDesk Plus 11306 or later, ServiceDesk Plus MSP 10530 or later, and SupportCenter Plus 11014 or later, per vendor instructions (CISA KEV requires this action). Until patched, restrict or firewall internet access to /RestAPI endpoints, and review access logs for unauthenticated requests to the ImportTechnicians action along with unexpected processes, files, or webshells on the server. Given the 93.3% EPSS score, active APT exploitation, and concurrent zero-day activity against other ManageEngine products, treat exposed instances as potentially compromised and hunt for post-exploitation activity.

9.893% KEV PoC
  • zohocorp ManageEngine ServiceDesk Plus all versions before 11306
  • zohocorp ManageEngine ServiceDesk Plus MSP all versions before 10530
  • zohocorp ManageEngine SupportCenter Plus all versions before 11014
largetens of thousands of on-prem help desk deployments worldwide, with thousands of instances directly internet-exposed (estimate)
CVE-2021-44515
Authentication Bypass Leading to RCE in Zoho ManageEngine Desktop Central

CVE-2021-44515 is an authentication bypass in Zoho ManageEngine Desktop Central and Desktop Central MSP that allows an unauthenticated attacker to execute arbitrary code on the central management server. It is triggered by sending crafted requests to the Desktop Central server without valid credentials, bypassing the login entirely. Successful exploitation yields code execution on the management server, which typically holds broad credentials and can push commands and agents to every managed endpoint, making it a strong foothold for further network compromise. Any organization running an on-premises Desktop Central or Desktop Central MSP server is affected, particularly where the server is internet-exposed. The flaw was under active exploitation when disclosed in December 2021: CISA added it to the KEV on 2021-12-10, EPSS shows a 99.9% 30-day exploitation probability, and no public PoC is known.

Do: Upgrade Desktop Central and Desktop Central MSP to build 10.1.2228.11 or later per ManageEngine's advisory, verifying the running build on the server's About page. Restrict internet access to the Desktop Central web console (default ports 8020/8383) and review server logs for unauthenticated access or unexpected code execution. Because a compromised management server often holds domain-level credentials, rotate credentials stored on or used by the server and watch managed endpoints for signs of follow-on compromise.

9.8100% KEV PoC
  • Zoho (ManageEngine) Desktop Central / Desktop Central MSP on-prem builds prior to the December 2021 fix (vendor advisory fixes it in build 10.1.2228.11; source data lists no version range)
largetens of thousands of on-prem server deployments, aggregating millions of managed endpoints via MSP deployments
Full article386 words · extracted from therecord.media · click to collapse

Zoho urged customers on Friday to update their ManageEngine servers and apply a software fix that patches a zero-day vulnerability that is currently being exploited in the wild.

Tracked as CVE-2021-44515, the vulnerability impacts Zoho ManageEngine Desktop Central, an endpoint management solution that companies use to manage their workers' devices.

In a security advisory, the company said it patched a bug that would have allowed attackers to bypass authentication and run malicious code on Desktop Central servers.

"As we are noticing indications of exploitation of this vulnerability, we strongly advise customers to update their installations to the latest build as soon as possible," the company told customers.

The company did not share any details about the threat actor(s) exploiting this bug, but the advisory comes after state-backed groups have already exploited two other vulnerabilities in ADSelfService Plus (CVE-2021-40539) and ServiceDesk Plus (CVE-2021-44077) software packages to compromise its customers' networks already.

Attacks against the first began as early as August, according to CrowdStrikeCISA, and Palo Alto Networks, and attacks against the second bug began in November, according to Palo Alto Networks and CISA.

According to Palo Alto Networks, the targets of these previous attacks included several organizations in the US defense sector. It is believed that the purpose of these attacks is cyber-espionage and data theft.

While it is currently unconfirmed that the same nation-state groups are behind the exploitation of this third vulnerability, companies should exercise caution and update their Zoho servers as soon as possible.

There are currently approximately 3,100 Zoho ManageEngine Desktop Central servers connected to the internet, ripe for exploitation.

While previously Zoho released some steps to discover if a server has been hacked, there are no such instructions or steps at the time of writing, meaning Zoho customers will also most likely have to initiate incident response procedures right after they patch and inspect servers for the presence of any suspicious files. They can start by looking for the webshells detailed in the two Palo Alto Network and CISA alerts first.

No previous article

No new articles

Catalin Cimpanu

is a cybersecurity reporter who previously worked at ZDNet and Bleeping Computer, where he became a well-known name in the industry for his constant scoops on new vulnerabilities, cyberattacks, and law enforcement actions against hackers.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/zoho-warns-of-new-zero-day-vulnerability-exploited-in-attacks