DLL Hijacking Vulnerability in Zoho ManageEngine Desktop Central MSP
CVE-2020-9367

7.8HIGH

Key Information:

Vendor

Zohocorp

Vendor
CVE Published:
18 March 2021

What is CVE-2020-9367?

The MPS Agent in Zoho ManageEngine Desktop Central MSP version 10.0.486 is vulnerable to a DLL Hijacking issue. Specifically, the executables dcinventory.exe and dcconfig.exe do not provide the complete path when attempting to load the CSUNSAPI.dll library, which is absent from the installation. This design flaw allows malicious actors to hijack the DLL, paving the way for code injection and potential privilege escalation to NT AUTHORITY\SYSTEM. This vulnerability poses significant security risks, making proper mitigation and patching essential for organizations using this software.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.