CVE-2014-7862
ManageEngine Desktop Central - Create Administrator
Severity Score
9.8
*CVSS v3
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
2
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
The DCPluginServelet servlet in ManageEngine Desktop Central and Desktop Central MSP before build 90109 allows remote attackers to create administrator accounts via an addPlugInUser action.
El servlet DCPluginServelet en ManageEngine Desktop Central y Desktop Central MSP en versiones anteriores a la build 90109 permite a los atacantes remotos crear cuentas de administrador mediante una acción addPlugInUser.
Desktop Central versions 7 and forward suffer from an add administrator vulnerability.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2014-10-05 CVE Reserved
- 2014-12-31 CVE Published
- 2015-01-15 First Exploit
- 2024-08-06 CVE Updated
- 2024-10-25 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (10)
URL | Tag | Source |
---|---|---|
http://packetstormsecurity.com/files/129769/Desktop-Central-Add-Administrator.html | Issue Tracking | |
http://seclists.org/fulldisclosure/2015/Jan/2 | Issue Tracking | |
http://www.securityfocus.com/archive/1/534356/100/0/threaded | Mailing List | |
http://www.securityfocus.com/bid/71849 | Third Party Advisory | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/99595 | Issue Tracking | |
https://github.com/pedrib/PoC/blob/master/advisories/ManageEngine/me_dc9_admin.txt | Third Party Advisory | |
https://www.manageengine.com/products/desktop-central/cve20147862-unauthorized-account-creation.html | Third Party Advisory | |
https://seclists.org/fulldisclosure/2015/Jan/2 |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/43892 | 2015-01-15 | |
https://www.rapid7.com/db/modules/auxiliary/admin/http/manage_engine_dc_create_admin | 2024-08-06 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Zohocorp Search vendor "Zohocorp" | Desktop Central Search vendor "Zohocorp" for product "Desktop Central" | < 90109 Search vendor "Zohocorp" for product "Desktop Central" and version " < 90109" | managed_service_providers |
Affected
| ||||||
Zohocorp Search vendor "Zohocorp" | Desktop Central Search vendor "Zohocorp" for product "Desktop Central" | >= 7 Search vendor "Zohocorp" for product "Desktop Central" and version " >= 7" | - |
Affected
|