Junglewise Threat Intelligence

CVE-2022-28810: Zoho ManageEngine ADSelfService Plus Remote Code Execution Vulnerability

CVE-2022-28810 · Severity: critical · CVSS 6.8 · Exploited in the wild · Published 2023-03-07

Technologies: Zoho ManageEngine. Vendors: Zoho.

Executive brief

Zoho ManageEngine ADSelfService Plus allows remote authenticated administrators to execute arbitrary OS commands as SYSTEM via a policy custom script feature. The vulnerability can be exploited due to the use of default administrator passwords or by injecting commands into unsanitized password fields during password change or reset operations.

Affected products

  • Zoho ManageEngine ADSelfService Plus before build 6122

Timeline

  • 2022-04-14: disclosed: Initial technical description and patch information published by Rapid7
  • 2023-03-07: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog
  • 2023-03-07: advisory: NVD publication date

Related threats