Executive brief
Zoho ManageEngine ADSelfService Plus is a self-service password reset and account unlock portal that integrates with Windows logon screens. Versions before build 7001 contain a remote code execution vulnerability in the embedded browser component that allows an attacker with access to the Windows logon screen to execute arbitrary code with system-level privileges, fully compromising the affected computer.
Technical details
The vulnerability exists in the GINA client's embedded (kiosk) browser used for displaying the Windows logon screen password reset portal. An attacker with local access to the logon screen can exploit improper error handling in the browser to execute code in the NT AUTHORITY\SYSTEM context. The issue was fixed in build 7001 by correcting error handling and hardening the embedded browser component.
Affected products
- Zoho ManageEngine ADSelfService Plus before build 7001
Timeline
- 2026-09-22: disclosed
- 2026-08-24: patched: Fixed in build 7001