QID 377635

Date Published: 2022-10-18

QID 377635: Zoho ManageEngine ADAudit Plus Arbitrary File Write Vulnerability

An unauthorized arbitrary file write vulnerability (CVE-2021-42847) in ManageEngine ADAudit Plus lets anyone to write and execute arbitrary files in the system.

Affected Version:
ADAudit Plus builds 7005 and earlier are affected.

QID Detection Logic (Authenticated):
This QID checks Windows Registry "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\New.exe" to get the installation path and checks "conf\product.conf" to check whether the build version is prior to 7006.

Successful exploitation of the vulnerability may allow remote attacker to write and execute arbitrary files in the system.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Customers are advised to upgrade to Zoho ManageEngine ADAudit Plus build 7006 or later. For more information please refer to Zoho Security Advisory

    CVEs related to QID 377635

    Software Advisories
    Advisory ID Software Component Link
    Zoho Security Advisory URL Logo pitstop.manageengine.com/portal/en/community/topic/fix-released-for-a-vulnerability-in-manageengine-adaudit-plus