Executive brief
Zoho ManageEngine Desktop Central is vulnerable to an authentication bypass that allows remote attackers to execute arbitrary code on the server. The vulnerability affects both Enterprise and MSP editions and has been observed being exploited in the wild.
Affected products
- Zoho ManageEngine Desktop Central Enterprise <= 10.1.2127.17, 10.1.2128.0 to 10.1.2137.2
- Zoho ManageEngine Desktop Central MSP <= 10.1.2127.17, 10.1.2128.0 to 10.1.2137.2
Timeline
- 2021-12-10: disclosed
- 2021-12-10: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-12-10: patched
- 2021-12-01: exploited: Exploited in the wild in December 2021