First published: Wed Sep 12 2018(Updated: )
An issue was discovered in Zoho ManageEngine Desktop Central before 10.0.282. A clickable company logo in a window running as SYSTEM can be abused to escalate privileges. In cloud, the issue is fixed in 10.0.470 agent version.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zohocorp Manageengine Desktop Central | <10.0.282 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-13411 is a vulnerability discovered in Zoho ManageEngine Desktop Central before version 10.0.282 that allows an attacker to escalate privileges using a clickable company logo in a window running as SYSTEM.
CVE-2018-13411 is classified as a critical vulnerability with a severity score of 8.8.
CVE-2018-13411 affects Zoho ManageEngine Desktop Central versions prior to 10.0.282.
To fix CVE-2018-13411, update to version 10.0.282 or higher of Zoho ManageEngine Desktop Central.
You can find more information about CVE-2018-13411 at the following references: [SecurityFocus](http://www.securityfocus.com/bid/105348), [GitHub](https://github.com/AJ-SA/Zoho-ManageEngine/blob/master/README.md), [ManageEngine](https://www.manageengine.com/products/desktop-central/elevation-of-system-privilege.html).