Authenticated Command Injection Vulnerability in Zoho ManageEngine Applications Manager
CVE-2025-9223
Key Information:
- Vendor
Zohocorp
- Vendor
- CVE Published:
- 11 November 2025
Badges
What is CVE-2025-9223?
Zoho's ManageEngine Applications Manager, specifically versions 178100 and earlier, is susceptible to an authenticated command injection vulnerability. This security flaw arises from incorrect configurations in the execute program action feature. Attackers with authenticated access could exploit this vulnerability to execute arbitrary commands, posing a significant threat to the integrity and confidentiality of the system. Users are strongly advised to apply available patches and updates to mitigate potential risks.
Affected Version(s)
ManageEngine Applications Manager 0 < 178200
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.