CVE-2018-13411: Critical severity manageengine desktop central vulnerability
An issue was discovered in Zoho ManageEngine Desktop Central before 10.0.282. A clickable company logo in a window running as SYSTEM can be abused to escalate privileges. In cloud, the issue is fixed in 10.0.470 agent version.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-13411?
CVE-2018-13411 is a vulnerability discovered in Zoho ManageEngine Desktop Central before version 10.0.282 that allows an attacker to escalate privileges using a clickable company logo in a window running as SYSTEM.
How severe is CVE-2018-13411?
CVE-2018-13411 is classified as a critical vulnerability with a severity score of 8.8.
How does CVE-2018-13411 affect Zoho ManageEngine Desktop Central?
CVE-2018-13411 affects Zoho ManageEngine Desktop Central versions prior to 10.0.282.
How can I fix CVE-2018-13411?
To fix CVE-2018-13411, update to version 10.0.282 or higher of Zoho ManageEngine Desktop Central.
Where can I find more information about CVE-2018-13411?
You can find more information about CVE-2018-13411 at the following references: [SecurityFocus](http://www.securityfocus.com/bid/105348), [GitHub](https://github.com/AJ-SA/Zoho-ManageEngine/blob/master/README.md), [ManageEngine](https://www.manageengine.com/products/desktop-central/elevation-of-system-privilege.html).