Warning: Yet Another Zoho ManageEngine Product Found Under Active Attacks
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-40539 | Unauthenticated RCE via REST API auth bypass in Zoho ManageEngine ADSelfService Plus CVE-2021-40539 is a critical (CVSS 9.8) authentication bypass in the REST API of Zoho ManageEngine ADSelfService Plus, caused by use of an incorrectly resolved name or reference (CWE-706). An unauthenticated, network-adjacent or internet-reachable attacker sends specially crafted requests to the product's REST API, bypassing authentication, and can chain the bypass to full remote code execution with no privileges or user interaction required. Successful exploitation yields complete compromise of the self-service portal server (high impact to confidentiality, integrity and availability); public reporting and vendor notes document attackers dropping malicious code and web shells onto vulnerable servers. Any organization running ManageEngine ADSelfService Plus build 6113 or earlier is affected, which typically means enterprise Microsoft Active Directory environments running this widely deployed self-service password/SSO portal. Exploitation is confirmed in the wild: the flaw was added to CISA KEV on 2021-11-03 with known ransomware use, EPSS puts the 30-day exploitation probability at 99% (100th percentile), Microsoft warned that Chinese threat actors were actively exploiting it, a public proof-of-concept is available, and it ranked among CISA's most routinely exploited vulnerabilities. Do: Immediately upgrade ManageEngine ADSelfService Plus to a fixed build newer than 6113 per the vendor's update instructions, as required by CISA. Because exploitation predates patching and the flaw has been used to drop malicious code, check ADSelfService Plus servers for web shells, unexpected scheduled tasks, and unexplained accounts/processes, and hunt for indicators from the published analyses. Where possible, restrict internet exposure of the ADSelfService Plus REST API while patching, prioritized for externally reachable instances. | 9.8 | 99% | KEV ransomware PoC |
| largetens of thousands of enterprise server installations (unknown precise count) | |
| CVE-2021-44077 | Unauthenticated RCE in Zoho ManageEngine ServiceDesk Plus and SupportCenter Plus CVE-2021-44077 is a critical (CVSS 9.8) unauthenticated remote code execution flaw in Zoho ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP, and SupportCenter Plus, rooted in missing authentication (CWE-306) on /RestAPI servlet URLs, specifically the ImportTechnicians action in the Struts configuration. A remote attacker can trigger it by sending crafted unauthenticated requests to the RestAPI endpoints, requiring no credentials or user interaction. Successful exploitation yields arbitrary code execution in the context of the application, giving attackers full control of the help desk server as a foothold for further network compromise. Any organization running affected versions before ServiceDesk Plus 11306, ServiceDesk Plus MSP 10530, or SupportCenter Plus 11014 is affected, particularly where the console is internet-facing. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2021-12-01, carries a 93.3% EPSS probability of near-term exploitation, and headlines point to active APT campaigns and mass exploitation against ManageEngine ServiceDesk deployments. Do: Upgrade to the fixed releases: ServiceDesk Plus 11306 or later, ServiceDesk Plus MSP 10530 or later, and SupportCenter Plus 11014 or later, per vendor instructions (CISA KEV requires this action). Until patched, restrict or firewall internet access to /RestAPI endpoints, and review access logs for unauthenticated requests to the ImportTechnicians action along with unexpected processes, files, or webshells on the server. Given the 93.3% EPSS score, active APT exploitation, and concurrent zero-day activity against other ManageEngine products, treat exposed instances as potentially compromised and hunt for post-exploitation activity. | 9.8 | 93% | KEV PoC |
| largetens of thousands of on-prem help desk deployments worldwide, with thousands of instances directly internet-exposed (estimate) | |
| CVE-2021-44515 | Authentication Bypass Leading to RCE in Zoho ManageEngine Desktop Central CVE-2021-44515 is an authentication bypass in Zoho ManageEngine Desktop Central and Desktop Central MSP that allows an unauthenticated attacker to execute arbitrary code on the central management server. It is triggered by sending crafted requests to the Desktop Central server without valid credentials, bypassing the login entirely. Successful exploitation yields code execution on the management server, which typically holds broad credentials and can push commands and agents to every managed endpoint, making it a strong foothold for further network compromise. Any organization running an on-premises Desktop Central or Desktop Central MSP server is affected, particularly where the server is internet-exposed. The flaw was under active exploitation when disclosed in December 2021: CISA added it to the KEV on 2021-12-10, EPSS shows a 99.9% 30-day exploitation probability, and no public PoC is known. Do: Upgrade Desktop Central and Desktop Central MSP to build 10.1.2228.11 or later per ManageEngine's advisory, verifying the running build on the server's About page. Restrict internet access to the Desktop Central web console (default ports 8020/8383) and review server logs for unauthenticated access or unexpected code execution. Because a compromised management server often holds domain-level credentials, rotate credentials stored on or used by the server and watch managed endpoints for signs of follow-on compromise. | 9.8 | 100% | KEV PoC |
| largetens of thousands of on-prem server deployments, aggregating millions of managed endpoints via MSP deployments |
Full article258 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananDec 04, 2021
Enterprise software provider Zoho on Friday warned that a newly patched critical flaw in its Desktop Central and Desktop Central MSP is being actively exploited by malicious actors, marking the third security vulnerability in its products to be abused in the wild in a span of four months.
The issue, assigned the identifier CVE-2021-44515, is an authentication bypass vulnerability that could permit an adversary to circumvent authentication protections and execute arbitrary code in the Desktop Central MSP server.
"If exploited, the attackers can gain unauthorized access to the product by sending a specially crafted request leading to remote code execution," Zoho cautioned in an advisory. "As we are noticing indications of exploitation of this vulnerability, we strongly advise customers to update their installations to the latest build as soon as possible."
The company has also made available an Exploit Detection Tool that will help customers identify signs of compromise in their installations.
With this development, CVE-2021-44515 joins two other vulnerabilities CVE-2021-44077 and CVE-2021-40539 that have been weaponized to compromise the networks of critical infrastructure organizations across the world.
The disclosure also comes a day after the U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that CVE-2021-44077 — an unauthenticated, remote code execution vulnerability affecting ServiceDesk Plus — is being exploited to drop web shells and carry out an array of post-exploitation activities as part of a campaign dubbed "TiltedTemple."
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2021/12/warning-yet-another-zoho-manageengine.html