CVE-2020-11552
Summary
| CVE | CVE-2020-11552 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-08-11 16:15:00 UTC |
| Updated | 2020-08-13 20:08:00 UTC |
| Description | An elevation of privilege vulnerability exists in ManageEngine ADSelfService Plus before build 6003 because it does not properly enforce user privileges associated with a Certificate dialog. This vulnerability could allow an unauthenticated attacker to escalate privileges on a Windows host. An attacker does not require any privilege on the target system in order to exploit this vulnerability. One option is the self-service option on the Windows login screen. Upon selecting this option, the thick-client software is launched, which connects to a remote ADSelfService Plus server to facilitate self-service operations. An unauthenticated attacker having physical access to the host could trigger a security alert by supplying a self-signed SSL certificate to the client. The View Certificate option from the security alert allows an attacker to export a displayed certificate to a file. This can further cascade to a dialog that can open Explorer as SYSTEM. By navigating from Explorer to \windows\system32, cmd.exe can be launched as a SYSTEM. |
Risk And Classification
Problem Types: CWE-269
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Zohocorp | Manageengine Adselfservice Plus | 6.0 | - | All | All |
| Application | Zohocorp | Manageengine Adselfservice Plus | 6.0 | 6000 | All | All |
| Application | Zohocorp | Manageengine Adselfservice Plus | 6.0 | 6001 | All | All |
| Application | Zohocorp | Manageengine Adselfservice Plus | 6.0 | 6002 | All | All |
| Application | Zohocorp | Manageengine Adselfservice Plus | 6.0 | - | All | All |
| Application | Zohocorp | Manageengine Adselfservice Plus | 6.0 | 6000 | All | All |
| Application | Zohocorp | Manageengine Adselfservice Plus | 6.0 | 6001 | All | All |
| Application | Zohocorp | Manageengine Adselfservice Plus | 6.0 | 6002 | All | All |
| Application | Zohocorp | Manageengine Adselfservice Plus | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| ManageEngine - IT Operations and Service Management Software | MISC | www.manageengine.com | Vendor Advisory |
| POPUP | CONFIRM | pitstop.manageengine.com | Release Notes, Vendor Advisory |
| Full Disclosure: ManageEngine ADSelfService Plus – Unauthenticated Remote Code Execution Vulnerability | MISC | seclists.org | Exploit, Mailing List, Third Party Advisory |
| ManageEngine ADSelfService Plus 6000 Remote Code Execution ≈ Packet Storm | MISC | packetstormsecurity.com | Exploit, Third Party Advisory, VDB Entry |
| Full Disclosure: Re: [FD] ManageEngine ADSelfService Plus – Unauthenticated Remote Code Execution Vulnerability | FULLDISC | seclists.org | Exploit, Mailing List, Third Party Advisory |
| ManageEngine ADSelfService Build prior to 6003 - Remote Code Execution (Unauthenticated) - Java webapps Exploit | MISC | www.exploit-db.com | Exploit, Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.