Bypass of USB Restrictions in Zoho ManageEngine Device Control Plus
CVE-2022-47577

7.8HIGH

Key Information:

Vendor

Zohocorp

Vendor
CVE Published:
20 December 2022

What is CVE-2022-47577?

A significant vulnerability exists in the endpoint protection agent of Zoho ManageEngine Device Control Plus, allowing users to bypass stringentUSB restrictions. Even after configuring the system to prevent data transfer from USB drives, memory cards, and mobile devices, the use of a virtual machine enables unauthorized data exfiltration. This can occur without leaving any trace in the Windows audit logs, compromising data security. Notably, the vendor asserts that this is not a vulnerability in their product, which raises concerns regarding the effectiveness of their security measures.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.