vendor:
Zoho ManageEngine ADManager Plus
by:
Digital Interruption
7
CVSS
HIGH
Privilege Escalation
Unknown
CWE
Product Name: Zoho ManageEngine ADManager Plus
Affected Version From: 6.6 (Build 6658)
Affected Version To: Unknown
Patch Exists: NO
Related CWE: CVE-2018-19374
CPE: Unknown
Platforms Tested: Windows Server 2012 R2
2019
Zoho ManageEngine ADManager Plus 6.6 (Build < 6659) Privilege Escalation
Due to weak permissions setup on the bin, lib and tools directories within the ManageEngine installation directory, it is possible for any authenticated user to modify several core files.To escalate privileges to that of LOCAL SYSTEM, drop a payload onto the system and then add a line to binChangeJRE.bat to execute it every time the system is rebooted.
Mitigation:
Unknown