Security News > 2023 > January > Zoho ManageEngine PoC Exploit to be Released Soon - Patch Before It's Too Late!
Users of Zoho ManageEngine are being urged to patch their instances against a critical security vulnerability ahead of the release of a proof-of-concept exploit code.
"This vulnerability allows an unauthenticated adversary to execute arbitrary code," Zoho warned in an advisory issued late last year, noting that it affects all ManageEngine setups that have the SAML single sign-on feature enabled, or had it enabled in the past.
Ai has now released Indicators of Compromise associated with the flaw, noting that it was able to successfully reproduce the exploit against ManageEngine ServiceDesk Plus and ManageEngine Endpoint Central products.
"The vulnerability is easy to exploit and a good candidate for attackers to 'spray and pray' across the internet," researcher James Horseman said.
Ai further called attention to the fact that there are more than 1,000 instances of ManageEngine products exposed to the internet with SAML currently enabled, potentially turning them into lucrative targets.
It's not uncommon for hackers to exploit awareness of a major vulnerability for malicious campaigns.
News URL
https://thehackernews.com/2023/01/zoho-manageengine-poc-exploit-to-be.html
Related news
- Adobe fixes Acrobat Reader zero-day with public PoC exploit (source)
- Adobe completes fix for Reader bug with known PoC exploit (CVE-2024-41869) (source)
- Exploit code released for critical Ivanti RCE flaw, patch now (source)
- PoC exploit for exploited Ivanti Cloud Services Appliance flaw released (CVE-2024-8190) (source)
- Qualcomm Urges OEMs to Patch Critical DSP and WLAN Flaws Amid Active Exploits (source)
- Microsoft SharePoint RCE flaw exploits in the wild – you've had 3 months to patch (source)
- Emergency patch: Cisco fixes bug under exploit in brute-force attacks (source)