First published: Tue Sep 29 2020(Updated: )
The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execute code and escalate privileges via spoofing. It does not authenticate the intended server before opening a browser window. An unauthenticated attacker capable of conducting a spoofing attack can redirect the browser to gain execution in the context of the WinLogon.exe process. If Network Level Authentication is not enforced, the vulnerability can be exploited via RDP. Additionally, if the web server has a misconfigured certificate then no spoofing attack is required
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zohocorp Manageengine Adselfservice Plus | <5.5 | |
Zohocorp Manageengine Adselfservice Plus | =5.5 | |
Zohocorp Manageengine Adselfservice Plus | =5.5-5500 | |
Zohocorp Manageengine Adselfservice Plus | =5.5-5501 | |
Zohocorp Manageengine Adselfservice Plus | =5.5-5502 | |
Zohocorp Manageengine Adselfservice Plus | =5.5-5503 | |
Zohocorp Manageengine Adselfservice Plus | =5.5-5504 | |
Zohocorp Manageengine Adselfservice Plus | =5.5-5505 | |
Zohocorp Manageengine Adselfservice Plus | =5.5-5506 | |
Zohocorp Manageengine Adselfservice Plus | =5.5-5507 | |
Zohocorp Manageengine Adselfservice Plus | =5.5-5508 | |
Zohocorp Manageengine Adselfservice Plus | =5.5-5509 | |
Zohocorp Manageengine Adselfservice Plus | =5.5-5510 | |
Zohocorp Manageengine Adselfservice Plus | =5.5-5511 | |
Zohocorp Manageengine Adselfservice Plus | =5.5-5512 | |
Zohocorp Manageengine Adselfservice Plus | =5.5-5513 | |
Zohocorp Manageengine Adselfservice Plus | =5.5-5514 | |
Zohocorp Manageengine Adselfservice Plus | =5.5-5515 | |
Zohocorp Manageengine Adselfservice Plus | =5.5-5516 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-5353 is a vulnerability in Zoho ManageEngine ADSelfService Plus that allows remote attackers to execute code and escalate privileges via spoofing.
CVE-2018-5353 has a severity rating of 9.8, which is considered critical.
CVE-2018-5353 works by exploiting a flaw in the custom GINA/CP module of Zoho ManageEngine ADSelfService Plus, which fails to authenticate the intended server before opening a browser window, allowing remote code execution and privilege escalation.
To fix the CVE-2018-5353 vulnerability, you should update Zoho ManageEngine ADSelfService Plus to version 5.5 build 5517 or later, as this version contains the necessary patch to address the vulnerability.
You can find more information about CVE-2018-5353 on the Zoho website, the GitHub repository for the vulnerability, and the release notes of Zoho ManageEngine ADSelfService Plus.