DLL Hijacking Vulnerability in Zoho ManageEngine Desktop Central MSP
CVE-2020-9367
What is CVE-2020-9367?
The MPS Agent in Zoho ManageEngine Desktop Central MSP version 10.0.486 is vulnerable to a DLL Hijacking issue. Specifically, the executables dcinventory.exe and dcconfig.exe do not provide the complete path when attempting to load the CSUNSAPI.dll library, which is absent from the installation. This design flaw allows malicious actors to hijack the DLL, paving the way for code injection and potential privilege escalation to NT AUTHORITY\SYSTEM. This vulnerability poses significant security risks, making proper mitigation and patching essential for organizations using this software.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved