CVE-2017-11346: Input Validation
Published Jul 16, 2017
·Updated
Zoho ManageEngine Desktop Central before build 100092 allows remote attackers to execute arbitrary code via vectors involving the upload of help desk videos.
Affected Software
1 affected component
ZohoCorp Manageengine Desktop Central<=10.0
Remediation
Event History
Jul 16, 2017
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-11346?
CVE-2017-11346 has a high severity rating due to the potential for remote code execution.
2
How do I fix CVE-2017-11346?
To fix CVE-2017-11346, upgrade to ManageEngine Desktop Central build 100092 or later.
3
What software is affected by CVE-2017-11346?
CVE-2017-11346 affects ManageEngine Desktop Central versions prior to build 100092.
4
Can CVE-2017-11346 be exploited remotely?
Yes, CVE-2017-11346 can be exploited remotely by attackers to execute arbitrary code.
5
What attack vectors are associated with CVE-2017-11346?
CVE-2017-11346 is associated with the upload of help desk videos as the primary attack vector.