CVE-2025-10020
Zoho ManageEngine ADManager Plus vulnerability analysis and mitigation

Overview

CVE-2025-10020 is an authenticated command injection vulnerability in the Custom Script component of Zohocorp ManageEngine ADManager Plus. It affects all versions before build 8024 (including 8.0-8001 through 8.0-8023 and all versions prior to 8.0), and was fixed on September 19, 2025, with public disclosure on October 21, 2025. The vulnerability carries a CVSS v3.1 base score of 8.8 (High) per NVD, and 9.9 (Critical) per ENISA/Zohocorp's own scoring (ManageEngine Advisory, Red Hat CVE).

Technical details

The root cause is improper neutralization of special elements used in OS commands (CWE-77) within the Custom Script component of ADManager Plus. An authenticated attacker with low-level privileges can inject arbitrary commands through this component, which fails to adequately sanitize user-supplied input before passing it to the underlying operating system. The attack is network-based, requires no user interaction, and has low attack complexity, making it straightforward to exploit once credentials are obtained. The vulnerability can lead to remote code execution (RCE) on the server (ManageEngine Advisory, Red Hat CVE).

Impact

Successful exploitation allows an authenticated attacker to execute arbitrary system commands on the ADManager Plus server, resulting in full compromise of confidentiality, integrity, and availability. An attacker could gain unauthorized access to sensitive Active Directory data, modify or delete data, disrupt service availability, and potentially use the compromised server as a pivot point for lateral movement within the Active Directory environment (ManageEngine Advisory, Red Hat CVE).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation. The EPSS score is approximately 0.79%, indicating a currently low probability of exploitation in the near term. The vulnerability was responsibly disclosed by researcher "bitxer" through Zoho's Bug Bounty program and is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (ManageEngine Advisory, Red Hat CVE).

Mitigation and workarounds

Zohocorp released a fix in ADManager Plus build 8024 on September 19, 2025. All users running build 8023 or earlier should upgrade immediately by installing the available service pack. As interim mitigations, organizations should implement network access controls to restrict exposure of the ADManager Plus interface, limit authentication credentials to necessary personnel only, and monitor Custom Script component activity for suspicious command patterns (ManageEngine Advisory).

Community reactions

The vulnerability received standard coverage from vulnerability tracking platforms and security aggregators shortly after disclosure on October 21, 2025. Greenbone included it in their October 2025 threat report, and it was noted by the security community on Mastodon/infosec.exchange. No major vendor statements beyond Zoho's own advisory or significant researcher commentary beyond the bug bounty reporter acknowledgment have been observed (Greenbone Threat Report).

Additional resources


SourceThis report was generated using AI

Related Zoho ManageEngine ADManager Plus vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-10020HIGH8.8
  • Zoho ManageEngine ADManager Plus logoZoho ManageEngine ADManager Plus
  • cpe:2.3:a:zohocorp:manageengine_admanager_plus
NoNoOct 21, 2025
CVE-2024-24409HIGH8.8
  • Zoho ManageEngine ADManager Plus logoZoho ManageEngine ADManager Plus
  • cpe:2.3:a:zohocorp:manageengine_admanager_plus
NoYesNov 08, 2024
CVE-2024-48878HIGH8.8
  • Zoho ManageEngine ADManager Plus logoZoho ManageEngine ADManager Plus
  • cpe:2.3:a:zohocorp:manageengine_admanager_plus
NoNoNov 04, 2024
CVE-2025-9435MEDIUM5.5
  • Zoho ManageEngine ADManager Plus logoZoho ManageEngine ADManager Plus
  • cpe:2.3:a:zohocorp:manageengine_admanager_plus
NoYesJan 13, 2026
CVE-2025-11670MEDIUM4.3
  • Zoho ManageEngine ADManager Plus logoZoho ManageEngine ADManager Plus
  • cpe:2.3:a:zohocorp:manageengine_admanager_plus
NoYesDec 15, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management