vendor:
                    ADManager Plus
                by:
                    Metin Yunus Kandemir
                6.1
                        CVSS
                    HIGH
                    Elevation of Privilege
                    269
                        CWE
                    Product Name: ADManager Plus
                    Affected Version From:  Build < 7210
                    Affected Version To:  Build 7210
                    Patch Exists: YES
                    Related CWE: CVE-2024-24409
                    CPE:  a:manageengine:admanager_plus:7203
                    Platforms Tested:  
                    2024
                    ManageEngine ADManager Plus Build < 7210 Elevation of Privilege Vulnerability
The vulnerability exists in ManageEngine ADManager Plus Build < 7210. A user with the 'Modify Computers' privilege in ADManager can alter attributes of computer objects in Active Directory, allowing them to set Constrained Kerberos Delegation and access services like CIFS, LDAP, and HOST services. This manipulation grants the user privileges they are not supposed to have, bypassing the normal restrictions.
Mitigation:
					Update to ADManager Plus Build 7210 or newer to fix this vulnerability. Restrict access to privileged roles and regularly review user privileges to prevent unauthorized access.