Executive brief
Zoho ManageEngine Desktop Central is vulnerable to unauthenticated remote code execution due to the deserialization of untrusted data in the getChartImage method of the FileStorage class. The vulnerability is accessible via the CewolfServlet and MDMLogUploaderServlet servlets.
Affected products
- Zoho ManageEngine Desktop Central before 10.0.474
Timeline
- 2020-03-06: disclosed: NVD Published Date
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: exploited: Reported as exploited in the wild