Junglewise Threat Intelligence

CVE-2020-10189: Zoho ManageEngine Desktop Central File Upload Vulnerability

CVE-2020-10189 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2021-11-03

Technologies: Zoho ManageEngine. Vendors: Zoho.

Executive brief

Zoho ManageEngine Desktop Central is vulnerable to unauthenticated remote code execution due to the deserialization of untrusted data in the getChartImage method of the FileStorage class. The vulnerability is accessible via the CewolfServlet and MDMLogUploaderServlet servlets.

Affected products

  • Zoho ManageEngine Desktop Central before 10.0.474

Timeline

  • 2020-03-06: disclosed: NVD Published Date
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: exploited: Reported as exploited in the wild

Related threats