Security News > 2020 > August > Critical ManageEngine ADSelfService Plus RCE flaw patched

Critical ManageEngine ADSelfService Plus RCE flaw patched
2020-08-10 09:15

A critical vulnerability in ManageEngine ADSelfService Plus, an Active Directory password-reset solution, could allow attackers to remotely execute commands with system level privileges on the target Windows host.

ManageEngine ADSelfService Plus is developed by ManageEngine, a division of Zoho Corporation, a software development company that focuses on web-based business tools and information technology.

"ADSelfService Plus supports self-service password reset for WFH and remote users by enabling users to reset Windows password from their own machines and updating the cached credentials through a VPN client," the company touts.

"A security alert can/will be triggered when 'an unauthenticated attacker having physical access to the host issues a self-signed SSLcertificate to the client'. Or, 'a self-signed SSLcertificate is configured on ADSelfService Plus server'," he noted.

Admins are advised to upgrade to ADSelfService Plus build 6003, which contains the complete security fix.


News URL

http://feedproxy.google.com/~r/HelpNetSecurity/~3/kEOwg1VLhWc/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Manageengine 9 0 3 4 3 10