SRC-2022-0002 : Zoho ManageEngine Desktop Central ChangeAmazonPasswordServlet Elevation of Privilege Vulnerability
CVE ID:
CVE-2022-23863
CVSS Score:
8.8, (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Affected Vendors:
Zoho
Affected Products:
ManageEngine Desktop Central and ManageEngine Desktop Central MSP <= 10.1.2138.1 (latest)
Vulnerability Details:
This vulnerability allows remote attackers to elevate privileges on affected installations of ManageEngine Desktop Central. Authentication as a low privileged user is required to exploit this vulnerability.
The specific flaw exists within the ChangeAmazonPasswordServlet class. The issue results from a lack of verification on the current password to be changed. An attacker can leverage this vulnerability to reset the administrators password.
Vendor Response:
Zoho has issued an update to correct this vulnerability. More details can be found at: https://www.manageengine.com/products/desktop-central/privilege-escalation-vulnerability.html
Disclosure Timeline:
- 2022-01-20 - Discovered and unreported
- 2022-01-21 - Public zero-day release of advisory
- 2022-01-25 - Zoho released a patch and advisory
Credit:
This vulnerability was discovered by Steven Seeley of Source Incite