CVE-2023-38743
ManageEngine ADManager Plus installServiceWithCredentials Command Injection Remote Code Execution Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Zoho ManageEngine ADManager Plus before Build 7200 allows admin users to execute commands on the host machine.
Zoho ManageEngine ADManager Plus anterior a Build 7200 permite a los usuarios administradores ejecutar comandos en la máquina de anfitrión.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of ManageEngine ADManager Plus. Authentication is required to exploit this vulnerability.
The specific flaw exists within the installServiceWithCredentials function. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the service account.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-07-25 CVE Reserved
- 2023-09-11 CVE Published
- 2023-10-02 First Exploit
- 2024-08-02 CVE Updated
- 2024-09-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://github.com/PetrusViet/CVE-2023-38743 | 2023-10-02 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.manageengine.com/products/ad-manager/admanager-kb/cve-2023-38743.html | 2023-09-13 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Zohocorp Search vendor "Zohocorp" | Manageengine Admanager Plus Search vendor "Zohocorp" for product "Manageengine Admanager Plus" | < 7.2 Search vendor "Zohocorp" for product "Manageengine Admanager Plus" and version " < 7.2" | - |
Affected
|