Executive brief
ManageEngine Endpoint Central is enterprise endpoint management software used to deploy patches and updates to Windows computers across organizations. During patch installation, the agent temporarily extracts JAR files into a user-writable directory, allowing a local attacker to replace those files and execute code with SYSTEM privileges, potentially gaining complete control over managed computers and the broader network.
Technical details
A privilege escalation vulnerability exists in the Endpoint Central agent during JAR file extraction triggered by patch scans. The root cause is that JAR files are extracted to a directory controlled by a standard user, enabling a local attacker to perform a directory hijacking or time-of-check-time-of-use (TOCTOU) attack to substitute malicious JAR files before extraction completes. The attack requires local filesystem access to the agent system and occurs during patch scan operations. Successful exploitation results in code execution with SYSTEM privileges. The vulnerability has been patched in versions 11.4.2540.23 and 11.5.2600.19 or later.
Affected products
- Zohocorp ManageEngine Endpoint Central below 11.4.2540.23 and below 11.5.2600.19
Timeline
- 2026-09-07: disclosed: CVE-2026-77697 published on NVD
- 2026-02-16: patched: Patch released for versions 11.4.2540.23 and 11.5.2600.19