QID 379293

Date Published: 2024-01-24

QID 379293: Zoho ManageEngine ADSelfService Plus Remote Code Execution (RCE) Vulnerability

ManageEngine ADSelfService Plus is a secure, web-based, end-user password reset management and single sign-on solution that helps domain users to perform self-service password reset, self-service account unlock, employee self-update of personal details (e.g., mobile numbers and photos) in Microsoft Windows Active Directory.

CVE-2024-0252 : ManageEngine ADSelfService Plus versions 6401 and below are vulnerable to the remote code execution due to the improper handling in the load balancer component. Authentication is required in order to exploit this vulnerability.

Affected Version:
Zoho ManageEngine ADSelfService Plus Builds 6401 and below

QID Detection Logic:
Authenticated : Checks for vulnerable version of ManageEngine ADSelfService Plus build 6401 and below

An authenticated user can execute remote codes on the machine where ADSelfService Plus is installed.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    The vendor has released a patch.
    Customers are advised to visit Zoho ManageEngine ADSelfService Plus Security Advisory for updates pertaining this vulnerability.
    Vendor References

    CVEs related to QID 379293

    Software Advisories
    Advisory ID Software Component Link
    Zoho ManageEngine ADSelfService Plus Security Advisory URL Logo www.manageengine.com/products/self-service-password/advisory/CVE-2024-0252.html