vendor:
Desktop Central
by:
Pedro Ribeiro
9,8
CVSS
CRITICAL
Administrator account creation (unauthenticated)
287
CWE
Product Name: Desktop Central
Affected Version From: v7 onwards
Affected Version To: v9.0 build 90109
Patch Exists: YES
Related CWE: CVE-2014-7862
CPE: a:manageengine:desktop_central
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
2014
Administrator account creation in ManageEngine Desktop Central / Desktop Central MSP
This vulnerability allows an attacker to create an administrator account without any authentication or other information needed. This can be done by sending a GET request to the Desktop Central server with the necessary parameters. This creates a new administrator user with the password 'admin', allowing the attacker to execute code on all devices managed by Desktop Central. A Metasploit auxiliary module has been released to exploit this vulnerability.
Mitigation:
Upgrade to version 9.0 build 90109 or later.