
Cloud Vulnerability DB
A community-led vulnerabilities database
Multiple Zoho ManageEngine products were found to contain a local privilege escalation vulnerability (CVE-2019-12133) discovered by Hashim Jawad from ACTIVELabs. The vulnerability was reported on March 22, 2019, and affected numerous ManageEngine products including Desktop Central v10.0.380, EventLog Analyzer v12.0.2, ServiceDesk Plus v10.0.0, and several others. The issue was officially fixed and released on June 1, 2019, in version 100393 (ActiveLabs Advisory).
The vulnerability stemmed from improper permissions configuration of the C:\ManageEngine directory and its sub-folders, which granted the Users group Create Files/write data permissions. The services associated with the affected products would attempt to execute several nonexistent binaries, such as sc.exe, from the current directory upon system start. This configuration flaw allowed non-privileged users to escalate their privileges to NT AUTHORITY\SYSTEM by placing a payload as one of the nonexistent binaries in the vulnerable folder (ActiveLabs Advisory, ManageEngine KB).
The vulnerability allowed unauthorized users with local access to escalate their privileges to NT AUTHORITY\SYSTEM level, effectively gaining complete control over the affected system. This could potentially lead to unauthorized system access and compromise of the entire system's security (ManageEngine KB).
The vulnerability could be exploited by local users who had access to the affected system. By placing a malicious payload in the form of one of the nonexistent binaries that the system attempted to execute, attackers could achieve privilege escalation to system-level access (ActiveLabs Advisory).
The vulnerability was addressed in version 100393 of the affected ManageEngine products. Users can apply the fix by logging into their ManageEngine console, clicking on their current build number on the top right corner, and updating to the latest build through the PPM update process (ManageEngine KB).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."