CVE-2017-16924: Critical severity ZohoCorp Manageengine Desktop Central vulnerability
Remote Information Disclosure and Escalation of Privileges in ManageEngine Desktop Central MSP 10.0.137 allows attackers to download unencrypted XML files containing all data for configuration policies via a predictable /client-data/<clientid>/collections/##/usermgmt.xml URL, as demonstrated by passwords and Wi-Fi keys. This is fixed in build 100157.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-16924?
The severity of CVE-2017-16924 is critical with a CVSS score of 9.8.
What is the vulnerability in ManageEngine Desktop Central MSP 10.0.137?
The vulnerability in ManageEngine Desktop Central MSP 10.0.137 allows attackers to download unencrypted XML files containing all data for configuration policies.
How can an attacker exploit CVE-2017-16924?
An attacker can exploit CVE-2017-16924 by accessing a predictable URL to download unencrypted XML files.
How can I fix CVE-2017-16924?
To fix CVE-2017-16924, update ManageEngine Desktop Central MSP to a version that includes a patch for this vulnerability.
Is there any additional information available about CVE-2017-16924?
Yes, you can find additional information about CVE-2017-16924 in the references provided: [GitHub](https://github.com/snoonan77/security-research/blob/master/CVE-2017-16924) and [ManageEngine](https://www.manageengine.com/desktop-management-msp/password-encryption-policy-violation.html).