CVE-2018-19374: High severity zoho corporation admanager plus vulnerability
Zoho ManageEngine ADManager Plus 6.6 Build 6657 allows local users to gain privileges (after a reboot) by placing a Trojan horse file into the permissive bin directory.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-19374?
CVE-2018-19374 is a vulnerability in Zoho ManageEngine ADManager Plus 6.6 Build 6657 that allows local users to gain privileges by placing a Trojan horse file into the permissive bin directory.
What is the severity of CVE-2018-19374?
The severity of CVE-2018-19374 is classified as high with a severity value of 7.
How does CVE-2018-19374 impact Zoho ManageEngine ADManager Plus?
CVE-2018-19374 allows local users to gain privileges in Zoho ManageEngine ADManager Plus 6.6 Build 6657.
How can this vulnerability be exploited?
This vulnerability can be exploited by placing a Trojan horse file into the permissive bin directory after a reboot.
Is there a fix available for CVE-2018-19374?
Yes, it is recommended to upgrade to a fixed version of Zoho ManageEngine ADManager Plus that does not have this vulnerability.