ManageEngine Security Update – 13 March 2024

ManageEngine has released a security update to address a critical vulnerability across Zoho ManageEngine Desktop Central version 9, build 90055.

The addressed vulnerability could allow the remote attacker to upload arbitrary files, execute arbitrary PHP code, and gain access to the affected system by sending a specially crafted HTTP request.

ManageEngine Desktop Central Unrestricted File Upload Vulnerability (CVE-2024-2370):

  • CVSS: 9.8
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Gain Access
Vulnerabilities

CVE-2024-2370

Mitigations

The enterprise should upgrade to the latest version of ManageEngine Endpoint Central (formerly Desktop Central) as soon as the testing phase is completed.

References