4.9
CVSSv2

CVE-2020-8838

Published: 23/03/2020 Updated: 07/10/2022
CVSS v2 Base Score: 4.9 | Impact Score: 6.4 | Exploitability Score: 4.4
CVSS v3 Base Score: 6.4 | Impact Score: 5.9 | Exploitability Score: 0.5
VMScore: 436
Vector: AV:A/AC:M/Au:S/C:P/I:P/A:P

Vulnerability Summary

An issue exists in Zoho ManageEngine AssetExplorer 6.5. During an upgrade of the Windows agent, it does not validate the source and binary downloaded. This allows an attacker on an adjacent network to execute code with NT AUTHORITY/SYSTEM privileges on the agent machines by providing an arbitrary executable via a man-in-the-middle attack.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

zohocorp manageengine assetexplorer 6.5

Exploits

The ManageEngine Asset Explorer windows agent suffers form a remote code execution vulnerability All versions prior to 1029 are affected ...