Privilege Escalation Vulnerability in ADManager Plus
CVE-2024-24409

8.8HIGH

Key Information:

Vendor
CVE Published:
8 November 2024

Summary

ManageEngine ADManager Plus, a product by ZohoCorp, is susceptible to a privilege escalation vulnerability that affects versions 7203 and earlier. This vulnerability is found within the 'Modify Computers' option, potentially allowing unauthorized users to escalate their privileges beyond intended access levels. Organizations utilizing this product should take precautionary measures to assess their current version and apply necessary updates to mitigate security risks.

Affected Version(s)

ADManager Plus Windows 0 <= 7203

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

metin kandemir
.