ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Attackers exploit another zero-day in ManageEngine software (CVE-2021-44515)

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-44077
Unauthenticated RCE in Zoho ManageEngine ServiceDesk Plus and SupportCenter Plus

CVE-2021-44077 is a critical (CVSS 9.8) unauthenticated remote code execution flaw in Zoho ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP, and SupportCenter Plus, rooted in missing authentication (CWE-306) on /RestAPI servlet URLs, specifically the ImportTechnicians action in the Struts configuration. A remote attacker can trigger it by sending crafted unauthenticated requests to the RestAPI endpoints, requiring no credentials or user interaction. Successful exploitation yields arbitrary code execution in the context of the application, giving attackers full control of the help desk server as a foothold for further network compromise. Any organization running affected versions before ServiceDesk Plus 11306, ServiceDesk Plus MSP 10530, or SupportCenter Plus 11014 is affected, particularly where the console is internet-facing. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2021-12-01, carries a 93.3% EPSS probability of near-term exploitation, and headlines point to active APT campaigns and mass exploitation against ManageEngine ServiceDesk deployments.

Do: Upgrade to the fixed releases: ServiceDesk Plus 11306 or later, ServiceDesk Plus MSP 10530 or later, and SupportCenter Plus 11014 or later, per vendor instructions (CISA KEV requires this action). Until patched, restrict or firewall internet access to /RestAPI endpoints, and review access logs for unauthenticated requests to the ImportTechnicians action along with unexpected processes, files, or webshells on the server. Given the 93.3% EPSS score, active APT exploitation, and concurrent zero-day activity against other ManageEngine products, treat exposed instances as potentially compromised and hunt for post-exploitation activity.

9.893% KEV PoC
  • zohocorp ManageEngine ServiceDesk Plus all versions before 11306
  • zohocorp ManageEngine ServiceDesk Plus MSP all versions before 10530
  • zohocorp ManageEngine SupportCenter Plus all versions before 11014
largetens of thousands of on-prem help desk deployments worldwide, with thousands of instances directly internet-exposed (estimate)
CVE-2021-44515
Authentication Bypass Leading to RCE in Zoho ManageEngine Desktop Central

CVE-2021-44515 is an authentication bypass in Zoho ManageEngine Desktop Central and Desktop Central MSP that allows an unauthenticated attacker to execute arbitrary code on the central management server. It is triggered by sending crafted requests to the Desktop Central server without valid credentials, bypassing the login entirely. Successful exploitation yields code execution on the management server, which typically holds broad credentials and can push commands and agents to every managed endpoint, making it a strong foothold for further network compromise. Any organization running an on-premises Desktop Central or Desktop Central MSP server is affected, particularly where the server is internet-exposed. The flaw was under active exploitation when disclosed in December 2021: CISA added it to the KEV on 2021-12-10, EPSS shows a 99.9% 30-day exploitation probability, and no public PoC is known.

Do: Upgrade Desktop Central and Desktop Central MSP to build 10.1.2228.11 or later per ManageEngine's advisory, verifying the running build on the server's About page. Restrict internet access to the Desktop Central web console (default ports 8020/8383) and review server logs for unauthenticated access or unexpected code execution. Because a compromised management server often holds domain-level credentials, rotate credentials stored on or used by the server and watch managed endpoints for signs of follow-on compromise.

9.8100% KEV PoC
  • Zoho (ManageEngine) Desktop Central / Desktop Central MSP on-prem builds prior to the December 2021 fix (vendor advisory fixes it in build 10.1.2228.11; source data lists no version range)
largetens of thousands of on-prem server deployments, aggregating millions of managed endpoints via MSP deployments
Full article324 words · extracted from helpnetsecurity.com · click to collapse

A vulnerability (CVE-2021-44515) in ManageEngine Desktop Central is being leveraged in attacks in the wild to gain access to server running the vulnerable software.

CVE-2021-44515

About CVE-2021-44515

CVE-2021-44515 is an authentication bypass vulnerability that could be triggered by attackers by sending a specially crafted request, with the goal of achieving unauthenticated remote code execution.

The issue is considered critical by the company and affects ManageEngine Desktop Central – a unified endpoint management (UEM) solution – and ManageEngine Desktop Central MSP – endpoint management software for MSPs. If installations of the latter are compromised, attackers could use the access to compromise endpoints and networks of MSPs’s client organizations.

ManageEngine has fixed the vulnerability and is advising customers to take action. “As we are noticing indications of exploitation of this vulnerability, we strongly advise customers to update their installations to the latest build as soon as possible,” they noted.

They have also offered an exploit detection tool customers can use to check whether their installation has been compromised via this flaw; indicators of compromise; and advice on incident response actions to take whether or not they’ve been hit.

About the attacks

ManageEngine did not share the nature of the attacks.

Claire Tills, senior research engineer at Tenable, said there are no known public proofs-of-concept exploits for CVE-2021-44515 available as of December 6.

It seems likely that attackers have created their own, as it apparently happened for an authentication bypass vulnerability (CVE-2021-44077) in ManageEngine ServiceDesk Plus. Those attacks have been tied to an APT group that has been exploiting vulnerabilities in different ManageEngine solutions in the last five months.

Researchers with Palo Alto Networks’ Unit 42 have also urged MSPs to update their ManageEngine Password Manager Pro software, as they have found evidence the attackers might be preparing to leverage a known vulnerability affecting it.

UPDATE (December 21, 2021, 01:47 a.m. PT):

The FBI has released additional technical details about APTs exploiting CVE-2021-44515, as well as some IoCs.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2021/12/07/cve-2021-44515/