SRC-2022-0002 : Zoho ManageEngine Desktop Central ChangeAmazonPasswordServlet Elevation of Privilege Vulnerability

CVE ID:

CVE-2022-23863

CVSS Score:

8.8, (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)

Affected Vendors:

Zoho

Affected Products:

ManageEngine Desktop Central and ManageEngine Desktop Central MSP <= 10.1.2138.1 (latest)

Vulnerability Details:

This vulnerability allows remote attackers to elevate privileges on affected installations of ManageEngine Desktop Central. Authentication as a low privileged user is required to exploit this vulnerability.

The specific flaw exists within the ChangeAmazonPasswordServlet class. The issue results from a lack of verification on the current password to be changed. An attacker can leverage this vulnerability to reset the administrators password.

Vendor Response:

Zoho has issued an update to correct this vulnerability. More details can be found at: https://www.manageengine.com/products/desktop-central/privilege-escalation-vulnerability.html

Disclosure Timeline:

  • 2022-01-20 - Discovered and unreported
  • 2022-01-21 - Public zero-day release of advisory
  • 2022-01-25 - Zoho released a patch and advisory

Credit:

This vulnerability was discovered by Steven Seeley of Source Incite