CVE-2019-12133
Zoho ManageEngine EventLog Analyzer vulnerability analysis and mitigation

Overview

Multiple Zoho ManageEngine products were found to contain a local privilege escalation vulnerability (CVE-2019-12133) discovered by Hashim Jawad from ACTIVELabs. The vulnerability was reported on March 22, 2019, and affected numerous ManageEngine products including Desktop Central v10.0.380, EventLog Analyzer v12.0.2, ServiceDesk Plus v10.0.0, and several others. The issue was officially fixed and released on June 1, 2019, in version 100393 (ActiveLabs Advisory).

Technical details

The vulnerability stemmed from improper permissions configuration of the C:\ManageEngine directory and its sub-folders, which granted the Users group Create Files/write data permissions. The services associated with the affected products would attempt to execute several nonexistent binaries, such as sc.exe, from the current directory upon system start. This configuration flaw allowed non-privileged users to escalate their privileges to NT AUTHORITY\SYSTEM by placing a payload as one of the nonexistent binaries in the vulnerable folder (ActiveLabs Advisory, ManageEngine KB).

Impact

The vulnerability allowed unauthorized users with local access to escalate their privileges to NT AUTHORITY\SYSTEM level, effectively gaining complete control over the affected system. This could potentially lead to unauthorized system access and compromise of the entire system's security (ManageEngine KB).

Exploitability

The vulnerability could be exploited by local users who had access to the affected system. By placing a malicious payload in the form of one of the nonexistent binaries that the system attempted to execute, attackers could achieve privilege escalation to system-level access (ActiveLabs Advisory).

Mitigation and workarounds

The vulnerability was addressed in version 100393 of the affected ManageEngine products. Users can apply the fix by logging into their ManageEngine console, clicking on their current build number on the top right corner, and updating to the latest build through the PPM update process (ManageEngine KB).

Additional resources


SourceThis report was generated using AI

Related Zoho ManageEngine EventLog Analyzer vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2021-44228CRITICAL10
  • IBM Db2 logoIBM Db2
  • cpe:2.3:a:cisco:sd-wan_vmanage
YesYesDec 10, 2021
CVE-2021-28959CRITICAL9.8
  • Zoho ManageEngine EventLog Analyzer logoZoho ManageEngine EventLog Analyzer
  • cpe:2.3:a:zohocorp:manageengine_eventlog_analyzer
NoYesApr 30, 2021
CVE-2023-35785HIGH8.1
  • Zoho ManageEngine EventLog Analyzer logoZoho ManageEngine EventLog Analyzer
  • cpe:2.3:a:zohocorp:manageengine_adaudit_plus
NoYesAug 28, 2023
CVE-2021-44832MEDIUM6.6
  • IBM Db2 logoIBM Db2
  • hive-container-v4.8.0
NoYesDec 28, 2021
CVE-2021-45105MEDIUM5.9
  • IBM Db2 logoIBM Db2
  • openshift4::ose-logging-elasticsearch6@sha256:f1a53e3be27c714226869b259c8eed80ac797b0cb83fbc2d786a9bba383d9547_amd64
NoYesDec 18, 2021

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management