CVE-2019-12876

HIGH

Zohocorp Manageengine Admanager Plus - Incorrect Permission Assignment

Title source: rule
STIX 2.1

Description

Zoho ManageEngine ADManager Plus 6.6.5, ADSelfService Plus 5.7, and DesktopCentral 10.0.380 have Insecure Permissions, leading to Privilege Escalation from low level privileges to System.

References (2)

Core 2
Core References
Exploit, Third Party Advisory x_refsource_misc
https://www.criticalstart.com/2019/07/manageengine-privilege-escalation/
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/109298

Scores

CVSS v3 7.3
EPSS 0.0010
EPSS Percentile 27.3%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-732
Status published
Products (3)
zohocorp/manageengine_admanager_plus 6.6.5
zohocorp/manageengine_adselfservice_plus 5.7
zohocorp/manageengine_desktop_central 10.0.380
Published Jul 17, 2019
Tracked Since Feb 18, 2026