
Cloud Vulnerability DB
A community-led vulnerabilities database
A privilege escalation vulnerability was identified in Zohocorp ManageEngine ADManager Plus versions 7203 and prior, specifically affecting the Modify Computers option. The vulnerability was discovered and assigned CVE-2024-24409, with the fix being released on September 29, 2023, in version 7210 (ManageEngine KB).
The vulnerability stems from misconfigured permissions in the built-in help desk roles, specifically affecting the Modify Computers role for managing custom attributes of computers. The issue has been classified as having a High severity rating (ManageEngine KB).
The vulnerability allowed technicians with the Modify Computers role to manage Additional Custom Attributes for computers in ADManager Plus, exceeding their intended permissions due to misconfigured access controls (ManageEngine KB).
The vulnerability has been addressed in build 7210. Organizations using affected versions are advised to update their ADManager Plus instance to the latest build by installing the service pack. The fix implements proper access control mechanisms to prevent unauthorized privilege escalation (ManageEngine KB).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."