Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2023-38743: Authenticated RCE vulnerability in ADManager Plus | CVE

Zoho ManageEngine ADManager Plus before Build 7200 allows admin users to execute commands on the host machine.

CVE
#vulnerability#web#mac#rce#auth#zero_day

Vulnerability details

Severity

Low

CVE ID

CVE- 2023-38743

Affected software versions

Build 7188 and older

Fixed version

Build 7200

Fixed on

June 13, 2023

Details

In ADManager Plus builds 7188 and older, an authenticated RCE vulnerability was reported. This has been fixed in the build 7200 and the release notes for it can be found here.

Impact

Authenticated users with admin privileges can run an arbitrary command on the host machine in which ADManager Plus is installed.

Steps to update

Update ADManager Plus instance to its latest build by installing the service pack.

Acknowledgement

This issue was reported anonymously by a user on Trend Micro’s Zero Day Initiative Published Advisories website.

Select a language to translate the contents of this web page:

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907