vendor:
ADManager Plus
by:
Metin Yunus Kandemir
6.1
CVSS
HIGH
Elevation of Privilege
269
CWE
Product Name: ADManager Plus
Affected Version From: Build < 7210
Affected Version To: Build 7210
Patch Exists: YES
Related CWE: CVE-2024-24409
CPE: a:manageengine:admanager_plus:7203
Platforms Tested:
2024
ManageEngine ADManager Plus Build < 7210 Elevation of Privilege Vulnerability
The vulnerability exists in ManageEngine ADManager Plus Build < 7210. A user with the 'Modify Computers' privilege in ADManager can alter attributes of computer objects in Active Directory, allowing them to set Constrained Kerberos Delegation and access services like CIFS, LDAP, and HOST services. This manipulation grants the user privileges they are not supposed to have, bypassing the normal restrictions.
Mitigation:
Update to ADManager Plus Build 7210 or newer to fix this vulnerability. Restrict access to privileged roles and regularly review user privileges to prevent unauthorized access.