CVE-2022-47577
HIGHZoho ManageEngine Device Control Plus 10.1.2228.15 - Info Disclosure
Title source: llmDescription
An issue was discovered in the endpoint protection agent in Zoho ManageEngine Device Control Plus 10.1.2228.15. Despite configuring complete restrictions on USB pendrives, USB HDD devices, memory cards, USB connections to mobile devices, etc., it is still possible to bypass the USB restrictions by making use of a virtual machine (VM). This allows a file to be exchanged outside the laptop/system. VMs can be created by any user (even without admin rights). The data exfiltration can occur without any record in the audit trail of Windows events on the host machine. NOTE: the vendor's position is "it's not a vulnerability in our product."
References (2)
Core 2
Core References
Scores
CVSS v3
7.1
EPSS
0.0004
EPSS Percentile
12.0%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
Status
published
Products (1)
zohocorp/manageengine_device_control_plus
10.1.2228.15
Published
Dec 20, 2022
Tracked Since
Feb 18, 2026