Executive brief
Zoho ManageEngine ADSelfService Plus allows remote authenticated administrators to execute arbitrary OS commands as SYSTEM via a policy custom script feature. The vulnerability can be exploited due to the use of default administrator passwords or by injecting commands into unsanitized password fields during password change or reset operations.
Affected products
- Zoho ManageEngine ADSelfService Plus before build 6122
Timeline
- 2022-04-14: disclosed: Initial technical description and patch information published by Rapid7
- 2023-03-07: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog
- 2023-03-07: advisory: NVD publication date