CVE-2018-5353: Critical severity ZohoCorp ManageEngine ADSelfService Plus vulnerability
The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execute code and escalate privileges via spoofing. It does not authenticate the intended server before opening a browser window. An unauthenticated attacker capable of conducting a spoofing attack can redirect the browser to gain execution in the context of the WinLogon.exe process. If Network Level Authentication is not enforced, the vulnerability can be exploited via RDP. Additionally, if the web server has a misconfigured certificate then no spoofing attack is required
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Zoho ManageEngine ADSelfService Plusto a version that resolves this vulnerability.Fixed in 5.5 build 5517 - Configuration
If the web server has a misconfigured certificate, correct it; the material notes that when certificates are correctly configured, no spoofing attack is required.
Web server (certificate configuration) TLS/SSL certificate configuration = configured correctly - Compensating control
Ensure Network Level Authentication (NLA) is enforced to prevent exploitation via RDP.
Event History
Frequently Asked Questions
What is CVE-2018-5353?
CVE-2018-5353 is a vulnerability in Zoho ManageEngine ADSelfService Plus that allows remote attackers to execute code and escalate privileges via spoofing.
How severe is CVE-2018-5353?
CVE-2018-5353 has a severity rating of 9.8, which is considered critical.
How does CVE-2018-5353 work?
CVE-2018-5353 works by exploiting a flaw in the custom GINA/CP module of Zoho ManageEngine ADSelfService Plus, which fails to authenticate the intended server before opening a browser window, allowing remote code execution and privilege escalation.
How can I fix the CVE-2018-5353 vulnerability?
To fix the CVE-2018-5353 vulnerability, you should update Zoho ManageEngine ADSelfService Plus to version 5.5 build 5517 or later, as this version contains the necessary patch to address the vulnerability.
Where can I find more information about CVE-2018-5353?
You can find more information about CVE-2018-5353 on the Zoho website, the GitHub repository for the vulnerability, and the release notes of Zoho ManageEngine ADSelfService Plus.