QID 377635
Date Published: 2022-10-18
QID 377635: Zoho ManageEngine ADAudit Plus Arbitrary File Write Vulnerability
An unauthorized arbitrary file write vulnerability (CVE-2021-42847) in ManageEngine ADAudit Plus lets anyone to write and execute arbitrary files in the system.
Affected Version:
ADAudit Plus builds 7005 and earlier are affected.
QID Detection Logic (Authenticated):
This QID checks Windows Registry "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\New.exe" to get the installation path and checks "conf\product.conf" to check whether the build version is prior to 7006.
Successful exploitation of the vulnerability may allow remote attacker to write and execute arbitrary files in the system.
Solution
Customers are advised to upgrade to Zoho ManageEngine ADAudit Plus build 7006 or later. For more information please refer to Zoho Security Advisory
Vendor References
CVEs related to QID 377635
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Zoho Security Advisory |
|