Bypass of USB Restrictions in Zoho ManageEngine Device Control Plus
CVE-2022-47577
Key Information:
- Vendor
Zohocorp
- Vendor
- CVE Published:
- 20 December 2022
What is CVE-2022-47577?
A significant vulnerability exists in the endpoint protection agent of Zoho ManageEngine Device Control Plus, allowing users to bypass stringentUSB restrictions. Even after configuring the system to prevent data transfer from USB drives, memory cards, and mobile devices, the use of a virtual machine enables unauthorized data exfiltration. This can occur without leaving any trace in the Windows audit logs, compromising data security. Notably, the vendor asserts that this is not a vulnerability in their product, which raises concerns regarding the effectiveness of their security measures.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved