7.2
CVSSv2

CVE-2018-13412

Published: 12/09/2018 Updated: 21/04/2021
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

An issue exists in the Self Service Portal in Zoho ManageEngine Desktop Central prior to 10.0.282. A clickable company logo in a window running as SYSTEM can be abused to escalate privileges. In cloud, the issue is fixed in 10.0.470 agent version.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

zohocorp manageengine desktop central

Github Repositories

https://www.manageengine.com/products/desktop-central/elevation-of-system-privilege.html

Zoho ManageEngine Local Privilege Escalation Reference: wwwmanageenginecom/products/desktop-central/elevation-of-system-privilegehtml CVEs: CVE-2018-13411, CVE-2018-13412 Application: Desktop Central Agent, Self Service Portal Desktop Central Notification Date: July 5, 2018 What was the Problem? Unauthorized users, whose computer is installed with Desktop Central A