430,000 FortiGate Devices Exposed in FortiBleed Ransomware Link|Adobe fixed multiple maximum-severity flaws in ColdFusion and Campaign Classic|Alleged Scattered Spider Hacker Extradited to U.S. to Face Cybercrime Charges|Oracle E-Business Suite Flaw Under Active Attack, 950 Systems Exposed|Azure CLI Targeted in LSHIY Password Spray Campaign Across 64 Orgs|CISA Warns BlueHammer Flaw Is Now Exploited in Ransomware Attacks|RustDuck: The Botnet That’s Still Small but Engineering Like It Plans to Grow|GuardFall Flaw Hits 10 of 11 Popular Open-Source AI Agents|XSS.is, The Forum That Ran the Ransomware Supply Chain Is Down. The Market Isn’t|U.S. CISA adds SimpleHelp flaw to its Known Exploited Vulnerabilities catalog|Hackers Steal Data of 4.38 Million Aflac Japan Customers|Apple Fixes WebKit Flaws in iOS and macOS, With Help From AI Tools|430,000 FortiGate Devices Exposed in FortiBleed Ransomware Link|Adobe fixed multiple maximum-severity flaws in ColdFusion and Campaign Classic|Alleged Scattered Spider Hacker Extradited to U.S. to Face Cybercrime Charges|Oracle E-Business Suite Flaw Under Active Attack, 950 Systems Exposed|Azure CLI Targeted in LSHIY Password Spray Campaign Across 64 Orgs|CISA Warns BlueHammer Flaw Is Now Exploited in Ransomware Attacks|RustDuck: The Botnet That’s Still Small but Engineering Like It Plans to Grow|GuardFall Flaw Hits 10 of 11 Popular Open-Source AI Agents|XSS.is, The Forum That Ran the Ransomware Supply Chain Is Down. The Market Isn’t|U.S. CISA adds SimpleHelp flaw to its Known Exploited Vulnerabilities catalog|Hackers Steal Data of 4.38 Million Aflac Japan Customers|Apple Fixes WebKit Flaws in iOS and macOS, With Help From AI Tools|
Advertisement

Ad Placeholder

Full Width × 90

Breaking News

Expert publicly discloses Zoho ManageEngine zero-day on Twitter

A security researcher has disclosed details and PoC code for a zero-day vulnerability in the Zoho ManageEngine product via Twitter. A security expert has disclosed details about a zero-day vulnerability in a Zoho enterprise product via Twitter, a circumstance that could cause serious problems to customers of the company. The flaw affects Zoho ManageEngine Desktop Central […]

Zoho ManageEngine Known Exploited Vulnerabilities Catalog

A security researcher has disclosed details and PoC code for a zero-day vulnerability in the Zoho ManageEngine product via Twitter.

A security expert has disclosed details about a zero-day vulnerability in a Zoho enterprise product via Twitter, a circumstance that could cause serious problems to customers of the company.

The flaw affects Zoho ManageEngine Desktop Central endpoint management solution that helps organizations in managing servers, laptops, desktops, smartphones, and tablets from a central location.

A researcher named Steven Seeley, disclosed technical details and the proof-of-concept code for the Zoho zero-day issue.

“This vulnerability allows remote attackers to execute arbitrary code on affected installations of ManageEngine Desktop Central. Authentication is not required to exploit this vulnerability.” read the advisory published by the expert.

“The specific flaw exists within the FileStorage class. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code under the context of SYSTEM.”

The vulnerability resides in the FileStorage class, it is caused by the lack of proper validation of user-supplied data. The attackers can exploit the vulnerability to execute code under the context of SYSTEM and take full control of the vulnerable ManageEngine systems,

The zero-day could be used by threat actors to target organizations and managed service providers (MSPs) using Zoho ManageEngine to deliver malware, especially ransomware.

Searching for exposed Zoho ManageEngine systems online using Shodan we can find over 2300 installs.

Experts also warn that Zoho ManageEngine systems that are not exposed online could be targeted by threat actors once compromised the hosting network. Then attackers can exploit the issue to deliver malware to all the systems on the company’s network.

Experts believe that the availability of a PoC exploit code for the vulnerability will trigger a new wave of attacks targeting the Zoho ManageEngine systems.

At the time there is no fix for the flaw, the company declared that it was not informed by Seeley about the issue and is currently working on a patch. On the other site, Seeley claimed on Twitter that Zoho usually ignored researchers.

Update 06/03/2020

The remote code execution vulnerability in Desktop Central (CVE-2020-10189) has been fixed in build 10.0.479, available at https://manageengine.com/products/desktop-central/service-packs.html…. For more information about the vulnerability, please visit https://t.co/uJedc7dexl

[adrotate banner=”9″] [adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, Zoho ManageEngine)

[adrotate banner=”5″]

[adrotate banner=”13″]