CVE-2023-26601
Zoho ManageEngine ServiceDesk Plus vulnerability analysis and mitigation

Overview

A denial-of-service vulnerability was identified in multiple Zoho ManageEngine products, including ServiceDesk Plus (through version 14104), Asset Explorer (through version 6987), ServiceDesk Plus MSP (before version 14000), and Support Center Plus (before version 14000). The vulnerability was discovered by Piotr Bazydlo of Trend Micro Zero Day Initiative and was officially reported on November 21, 2022, with fixes released starting January 24, 2023 (ManageEngine Advisory, ZDI Advisory).

Technical details

The vulnerability exists within the ImageUploadServlet component and stems from improper input validation. The flaw allows attackers to exploit the way an API method allocates memory by sending a small image file with a large size defined in the header. The vulnerability has been assigned a CVSS score of 6.5 (AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H), indicating medium severity with network attack vector, low attack complexity, and requiring low privileges (ZDI Advisory).

Impact

When successfully exploited, this vulnerability can cause the application to crash or become unresponsive, resulting in users being unable to access the application. The impact is primarily focused on service availability, with no direct effect on confidentiality or integrity (ManageEngine Advisory).

Mitigation and workarounds

ManageEngine has released fixes for all affected products: ServiceDesk Plus version 14104 (released January 24, 2023), ServiceDesk Plus MSP version 14001 (released February 16, 2023), SupportCenter Plus version 14001 (released February 20, 2023), and AssetExplorer version 6988 (released January 24, 2023). The fix includes implementation of limits for image pixel size and type validation for parameters. Users are advised to upgrade to these versions by downloading and applying the latest upgrade packs from the respective product pages (ManageEngine Advisory).

Additional resources


SourceThis report was generated using AI

Related Zoho ManageEngine ServiceDesk Plus vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-8309HIGH8.1
  • Zoho ManageEngine ServiceDesk PlusZoho ManageEngine ServiceDesk Plus
  • cpe:2.3:a:zohocorp:manageengine_servicedesk_plus
NoYesAug 20, 2025
CVE-2024-41150MEDIUM6.1
  • Zoho ManageEngine ServiceDesk PlusZoho ManageEngine ServiceDesk Plus
  • cpe:2.3:a:zohocorp:manageengine_servicedesk_plus
NoYesAug 23, 2024
CVE-2024-50053MEDIUM5.4
  • Zoho ManageEngine ServiceDesk PlusZoho ManageEngine ServiceDesk Plus
  • cpe:2.3:a:zohocorp:manageengine_servicedesk_plus
NoYesMar 21, 2025
CVE-2024-38869MEDIUM5.4
  • Zoho ManageEngine ServiceDesk PlusZoho ManageEngine ServiceDesk Plus
  • cpe:2.3:a:zohocorp:manageengine_supportcenter_plus
NoYesAug 23, 2024
CVE-2024-27314LOW2.4
  • Zoho ManageEngine ServiceDesk PlusZoho ManageEngine ServiceDesk Plus
  • cpe:2.3:a:zohocorp:manageengine_servicedesk_plus
NoYesMay 27, 2024

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management