First published: Thu Jan 04 2018(Updated: )
The DCPluginServelet servlet in ManageEngine Desktop Central and Desktop Central MSP before build 90109 allows remote attackers to create administrator accounts via an addPlugInUser action.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
zohocorp Desktop Central | <90109 | |
zohocorp Desktop Central | >=7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-7862 is classified as a critical vulnerability due to its potential for remote exploitation.
To fix CVE-2014-7862, upgrade ManageEngine Desktop Central and Desktop Central MSP to a version later than build 90109.
CVE-2014-7862 allows remote attackers to create unauthorized administrator accounts, compromising system security.
ManageEngine Desktop Central and Desktop Central MSP versions prior to build 90109 are affected by CVE-2014-7862.
Yes, CVE-2014-7862 can be exploited remotely, allowing attackers to gain administrative access.