CVE-2021-44515
Description
Zoho ManageEngine Desktop Central is vulnerable to authentication bypass, leading to remote code execution on the server, as exploited in the wild in December 2021. For Enterprise builds 10.1.2127.17 and earlier, upgrade to 10.1.2127.18. For Enterprise builds 10.1.2128.0 through 10.1.2137.2, upgrade to 10.1.2137.3. For MSP builds 10.1.2127.17 and earlier, upgrade to 10.1.2127.18. For MSP builds 10.1.2128.0 through 10.1.2137.2, upgrade to 10.1.2137.3.
Summary dbcve.org
An authentication bypass vulnerability in Zoho ManageEngine Desktop Central allows unauthenticated remote attackers to execute arbitrary code on the underlying server. The flaw was actively exploited in the wild in late 2021, which is consistent with its critical CVSS 9.8 rating, and affects both Enterprise and MSP build lines of the product.
Mitigation
Upgrade Desktop Central to the fixed vendor build: Enterprise/MSP builds 10.1.2127.17 or earlier must move to 10.1.2127.18, while builds 10.1.2128.0 through 10.1.2137.2 must move to 10.1.2137.3. Because the issue was exploited in the wild, apply the patch as an emergency change and review the host for indicators of compromise (unauthorized accounts, web shells, scheduled tasks, suspicious child processes) before and after upgrading.