Rewterz
Rewterz Threat Alert – CrySIS aka Dharma Ransomware – Active IOCs
January 18, 2022
Rewterz
Rewterz Threat Alert – AZORult Malware – Active IOCs
January 18, 2022

Rewterz Threat Advisory – CVE-2021-44757 – Zoho Fixes Critical Vulnerability

Severity

High

Analysis Summary

CVE-2021-44757

Zoho ManageEngine Desktop Central and Desktop Central MSP could allow a remote attacker to bypass security restrictions, caused by improper authentication validation. By sending a specially-crafted request, an attacker could exploit this vulnerability to read unauthorized data or write an arbitrary zip file on the server.

The company recommends customers to follow the security hardening guidelines for Desktop Central and Desktop Central MSP to secure their installs.

Impact

  • Bypass Security

Affected Vendors

  • Zoho

Affected Products

  • ManageEngine Desktop Central
  • Zoho ManageEngine Desktop Central MSP

Remediation

For patches, upgrades or suggested workaround information, refer to the following:

https://pitstop.manageengine.com/portal/en/community/topic/a-critical-security-patch-released-in-desktop-central-and-desktop-central-msp-for-cve-2021-44757-17-1-2022