header-logo
Suggest Exploit
vendor:
ADManager Plus
by:
Metin Yunus Kandemir
6.1
CVSS
HIGH
Elevation of Privilege
269
CWE
Product Name: ADManager Plus
Affected Version From: Build < 7210
Affected Version To: Build 7210
Patch Exists: YES
Related CWE: CVE-2024-24409
CPE: a:manageengine:admanager_plus:7203
Metasploit:
Other Scripts:
Platforms Tested:
2024

ManageEngine ADManager Plus Build < 7210 Elevation of Privilege Vulnerability

The vulnerability exists in ManageEngine ADManager Plus Build < 7210. A user with the 'Modify Computers' privilege in ADManager can alter attributes of computer objects in Active Directory, allowing them to set Constrained Kerberos Delegation and access services like CIFS, LDAP, and HOST services. This manipulation grants the user privileges they are not supposed to have, bypassing the normal restrictions.

Mitigation:

Update to ADManager Plus Build 7210 or newer to fix this vulnerability. Restrict access to privileged roles and regularly review user privileges to prevent unauthorized access.
Source

Exploit-DB raw data: