Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2018-5353


The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execute code and escalate privileges via spoofing. It does not authenticate the intended server before opening a browser window. An unauthenticated attacker capable of conducting a spoofing attack can redirect the browser to gain execution in the context of the WinLogon.exe process. If Network Level Authentication is not enforced, the vulnerability can be exploited via RDP. Additionally, if the web server has a misconfigured certificate then no spoofing attack is required


Published

2020-09-30T18:15:15.927

Last Modified

2024-11-21T04:08:38.213

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-290

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application zohocorp manageengine_adselfservice_plus < 5.5 Yes
Application zohocorp manageengine_adselfservice_plus 5.5 Yes
Application zohocorp manageengine_adselfservice_plus 5.5 Yes
Application zohocorp manageengine_adselfservice_plus 5.5 Yes
Application zohocorp manageengine_adselfservice_plus 5.5 Yes
Application zohocorp manageengine_adselfservice_plus 5.5 Yes
Application zohocorp manageengine_adselfservice_plus 5.5 Yes
Application zohocorp manageengine_adselfservice_plus 5.5 Yes
Application zohocorp manageengine_adselfservice_plus 5.5 Yes
Application zohocorp manageengine_adselfservice_plus 5.5 Yes
Application zohocorp manageengine_adselfservice_plus 5.5 Yes
Application zohocorp manageengine_adselfservice_plus 5.5 Yes
Application zohocorp manageengine_adselfservice_plus 5.5 Yes
Application zohocorp manageengine_adselfservice_plus 5.5 Yes
Application zohocorp manageengine_adselfservice_plus 5.5 Yes
Application zohocorp manageengine_adselfservice_plus 5.5 Yes
Application zohocorp manageengine_adselfservice_plus 5.5 Yes
Application zohocorp manageengine_adselfservice_plus 5.5 Yes
Application zohocorp manageengine_adselfservice_plus 5.5 Yes

References