Zoho fixes a critical vulnerability (CVE-2021
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-44515 | Authentication Bypass Leading to RCE in Zoho ManageEngine Desktop Central CVE-2021-44515 is an authentication bypass in Zoho ManageEngine Desktop Central and Desktop Central MSP that allows an unauthenticated attacker to execute arbitrary code on the central management server. It is triggered by sending crafted requests to the Desktop Central server without valid credentials, bypassing the login entirely. Successful exploitation yields code execution on the management server, which typically holds broad credentials and can push commands and agents to every managed endpoint, making it a strong foothold for further network compromise. Any organization running an on-premises Desktop Central or Desktop Central MSP server is affected, particularly where the server is internet-exposed. The flaw was under active exploitation when disclosed in December 2021: CISA added it to the KEV on 2021-12-10, EPSS shows a 99.9% 30-day exploitation probability, and no public PoC is known. Do: Upgrade Desktop Central and Desktop Central MSP to build 10.1.2228.11 or later per ManageEngine's advisory, verifying the running build on the server's About page. Restrict internet access to the Desktop Central web console (default ports 8020/8383) and review server logs for unauthenticated access or unexpected code execution. Because a compromised management server often holds domain-level credentials, rotate credentials stored on or used by the server and watch managed endpoints for signs of follow-on compromise. | 9.8 | 100% | KEV PoC |
| largetens of thousands of on-prem server deployments, aggregating millions of managed endpoints via MSP deployments | |
| CVE-2021-44757 | Zoho ManageEngine Desktop Central before 10.1.2137.9 and Desktop Central MSP before 10.1.2137.9 allow attackers to bypass authentication, and read sensitive inf Zoho ManageEngine Desktop Central before 10.1.2137.9 and Desktop Central MSP before 10.1.2137.9 allow attackers to bypass authentication, and read sensitive information or upload an arbitrary ZIP archive to the server. NVD description · AI analysis pending | 9.1 | 24% |
| — |
Full article237 words · extracted from securityaffairs.com · click to collapse

Zoho addressed a new critical severity flaw (CVE-2021-44757) that affects its Desktop Central and Desktop Central MSP unified endpoint management (UEM) solutions
Zoho fixed a new critical severity flaw, tracked as CVE-2021-44757, that affects its Desktop Central and Desktop Central MSP unified endpoint management (UEM) solutions.
The issue is an authentication bypass vulnerability, a remote attacker can exploit it to perform unauthorized actions in the server.
The Zoho ManageEngine Desktop Central endpoint management solution helps organizations in managing servers, laptops, desktops, smartphones, and tablets from a central location.
“An authentication bypass vulnerability that can allow a remote user to perform unauthorized actions in the server.” reads the advisory published by the Zoho’s ManageEngine Team. “If exploited, this vulnerability may allow an attacker to read unauthorized data or write an arbitrary zip file on the server. “
The company recommends customers to follow the security hardening guidelines for Desktop Central and Desktop Central MSP to secure their installs.
In December, The Federal Bureau of Investigation (FBI) revealed that another critical zero-day vulnerability in Zoho’s ManageEngine Desktop Central, tracked as CVE-2021-44515, has been under active exploitation by nation-state actors since at least October.
The CVE-2021-44515 flaw is an authentication bypass vulnerability in ManageEngine Desktop Central software that can be exploited by attackers to bypass authentication and execute arbitrary code on Desktop Central servers.
| [adrotate banner=”9″] | [adrotate banner=”12″] |
(SecurityAffairs – hacking, Zoho)
[adrotate banner=”5″]
[adrotate banner=”13″]
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/126828/security/zoho-desktop-central-cve-2021-44757-flaw.html