CVE-2020-8838
Summary
| CVE | CVE-2020-8838 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-03-23 17:15:00 UTC |
| Updated | 2022-10-07 14:14:00 UTC |
| Description | An issue was discovered in Zoho ManageEngine AssetExplorer 6.5. During an upgrade of the Windows agent, it does not validate the source and binary downloaded. This allows an attacker on an adjacent network to execute code with NT AUTHORITY/SYSTEM privileges on the agent machines by providing an arbitrary executable via a man-in-the-middle attack. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| AssetExplorer ITAM Solution ServicePacks Readme |
CONFIRM |
www.manageengine.com |
Release Notes, Vendor Advisory |
| ManageEngine Asset Explorer Windows Agent Remote Code Execution ≈ Packet Storm |
MISC |
packetstormsecurity.com |
|
| Full Disclosure: Asset Explorer Windows Agent - Remote Code Execution |
FULLDISC |
seclists.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 372459 Zoho ManageEngine AssetExplorer Remote code execution vulnerability