CVE-2020-15588

CRITICAL

ManageEngine Desktop Central < 10.0.561 - Remote Code Execution via Integer Overflow in InternetSendRequestEx

Title source: llm
STIX 2.1

Description

An issue was discovered in the client side of Zoho ManageEngine Desktop Central 10.0.552.W. An attacker-controlled server can trigger an integer overflow in InternetSendRequestEx and InternetSendRequestByBitrate that leads to a heap-based buffer overflow and Remote Code Execution with SYSTEM privileges. This issue will occur only when untrusted communication is initiated with server. In cloud, Agent will always connect with trusted communication.

References (1)

Core 1

Scores

CVSS v3 9.8
EPSS 0.0615
EPSS Percentile 90.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-190 CWE-787
Status published
Products (1)
zohocorp/manageengine_desktop_central < 10.0.561
Published Jul 29, 2020
Tracked Since Feb 18, 2026