CVE-2019-12876

HIGH

Zoho ManageEngine ADManager Plus, ADSelfService Plus, and DesktopCentral - Privilege Escalation via Insecure Permissions

Title source: llm
STIX 2.1

Description

Zoho ManageEngine ADManager Plus 6.6.5, ADSelfService Plus 5.7, and DesktopCentral 10.0.380 have Insecure Permissions, leading to Privilege Escalation from low level privileges to System.

References (2)

Core 2
Core References
Exploit, Third Party Advisory x_refsource_misc
https://www.criticalstart.com/2019/07/manageengine-privilege-escalation/
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/109298

Scores

CVSS v3 7.3
EPSS 0.0461
EPSS Percentile 90.5%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-732
Status published
Products (3)
zohocorp/manageengine_admanager_plus 6.6.5
zohocorp/manageengine_adselfservice_plus 5.7
zohocorp/manageengine_desktop_central 10.0.380
Published Jul 17, 2019
Tracked Since Feb 18, 2026