CVE-2025-11670
Zoho ManageEngine ADManager Plus vulnerability analysis and mitigation

Overview

CVE-2025-11670 is an NTLM Hash Exposure vulnerability in Zohocorp ManageEngine ADManager Plus affecting builds 8022 and older (all versions before build 8025). The vulnerability allows authorized technicians with specific privileges to retrieve the NTLM hash of the service account configured in ADManager Plus. It was disclosed on December 15, 2025, and fixed on October 13, 2025 in build 8025. The CVSS v3.1 base score is 4.3 (Medium) per NVD, though ENISA rates it 6.4 (Medium) under a broader scope vector (ManageEngine Advisory, Red Hat CVE).

Technical details

The root cause is classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). The vulnerability arises because ADManager Plus exposes the NTLM hash of its configured service account to technicians who have both NTFS Management permissions and the "Impersonate as Admin" option enabled. Exploitation requires network access and low-privilege authenticated access (a technician account with the specific permission set), but no user interaction. No public proof-of-concept code has been identified (ManageEngine Advisory, Red Hat CVE).

Impact

Successful exploitation allows a privileged technician to capture the NTLM hash of the ADManager Plus service account, which could then be used in pass-the-hash attacks or offline cracking attempts to gain unauthorized access to systems where that service account has privileges. This could facilitate lateral movement across connected Active Directory environments and lead to privilege escalation beyond the technician's intended access scope. Confidentiality is the primary impact, with no direct integrity or availability consequences (ManageEngine Advisory).

Exploitability

There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of disclosure. The EPSS score is approximately 0.033% (0.000330), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is constrained to authenticated technician accounts with the "Impersonate as Admin" permission enabled, significantly limiting the attack surface (Red Hat CVE).

Exploitation steps

  1. Identify target: Locate a ManageEngine ADManager Plus instance running build 8022 or earlier that is accessible over the network.
  2. Obtain technician credentials: Acquire credentials for a technician account that has NTFS Management permissions and the "Impersonate as Admin" option enabled — either through social engineering, credential theft, or insider access.
  3. Authenticate to ADManager Plus: Log in to the ADManager Plus web interface using the privileged technician account.
  4. Trigger NTLM hash exposure: Navigate to or invoke the NTFS Management functionality with impersonation enabled, causing the application to expose the NTLM hash of the configured service account in the request or response.
  5. Capture the NTLM hash: Intercept the exposed NTLM hash using a network proxy or monitoring tool.
  6. Leverage the hash: Use the captured NTLM hash in a pass-the-hash attack against other systems where the service account has privileges, or attempt offline cracking to recover the plaintext password (ManageEngine Advisory).

Indicators of compromise

  • Logs: ADManager Plus audit logs showing technician accounts accessing NTFS Management features with the "Impersonate as Admin" option, particularly from unexpected IP addresses or at unusual times.
  • Network: Unexpected outbound SMB/NTLM authentication attempts originating from the ADManager Plus server to external or unusual internal hosts; network captures showing NTLM challenge-response sequences involving the service account.
  • Behavioral: Technician accounts with "Impersonate as Admin" enabled performing NTFS Management operations outside of normal business hours or from new source IPs.
  • Authentication: Subsequent authentication events using the ADManager Plus service account from hosts or users that would not normally use that account, potentially indicating pass-the-hash activity.

Mitigation and workarounds

ManageEngine released a fix in ADManager Plus build 8025 (released October 13, 2025); all users should upgrade immediately from build 8022 or earlier. As an interim workaround, administrators should audit and restrict the "Impersonate as Admin" permission, granting it only to technicians who strictly require it. Additionally, organizations should review NTFS Management access controls, monitor for unusual service account authentication activity, and consider rotating the service account credentials as a precautionary measure (ManageEngine Advisory).

Community reactions

The vulnerability was responsibly disclosed through Zoho's Bug Bounty program by a researcher identified as "bitxer," and Zoho acknowledged the report and issued a fix prior to public disclosure. Rewterz published a threat advisory covering multiple Zoho ManageEngine vulnerabilities including this one (Rewterz Advisory). Community reaction has been limited given the medium severity and constrained exploitation prerequisites.

Additional resources


SourceThis report was generated using AI

Related Zoho ManageEngine ADManager Plus vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-10020HIGH8.8
  • Zoho ManageEngine ADManager Plus logoZoho ManageEngine ADManager Plus
  • cpe:2.3:a:zohocorp:manageengine_admanager_plus
NoNoOct 21, 2025
CVE-2024-24409HIGH8.8
  • Zoho ManageEngine ADManager Plus logoZoho ManageEngine ADManager Plus
  • cpe:2.3:a:zohocorp:manageengine_admanager_plus
NoYesNov 08, 2024
CVE-2024-48878HIGH8.8
  • Zoho ManageEngine ADManager Plus logoZoho ManageEngine ADManager Plus
  • cpe:2.3:a:zohocorp:manageengine_admanager_plus
NoNoNov 04, 2024
CVE-2025-9435MEDIUM5.5
  • Zoho ManageEngine ADManager Plus logoZoho ManageEngine ADManager Plus
  • cpe:2.3:a:zohocorp:manageengine_admanager_plus
NoYesJan 13, 2026
CVE-2025-11670MEDIUM4.3
  • Zoho ManageEngine ADManager Plus logoZoho ManageEngine ADManager Plus
  • cpe:2.3:a:zohocorp:manageengine_admanager_plus
NoYesDec 15, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management