CVE-2025-11670

MEDIUM

ManageEngine ADManager Plus < 8025 - NTLM Hash Exposure

Title source: llm
STIX 2.1

Description

Zohocorp ManageEngine ADManager Plus versions before 8025 are vulnerable to NTLM Hash Exposure.  This vulnerability is exploitable only by technicians who have the “Impersonate as Admin” option enabled.

References (1)

Core 1

Scores

CVSS v3 6.4
EPSS 0.0003
EPSS Percentile 8.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (2)
zohocorp/manageengine_admanager_plus 8.0 8000 (9 CPE variants)
zohocorp/manageengine_admanager_plus < 8.0
Published Dec 15, 2025
Tracked Since Feb 18, 2026