CVE-2019-11361: High severity zoho manageengine remote access plus vulnerability
Zoho ManageEngine Remote Access Plus 10.0.258 does not validate user permissions properly, allowing for privilege escalation and eventually a full application takeover.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-11361?
The severity of CVE-2019-11361 is high with a severity score of 8.8.
How does CVE-2019-11361 affect Zoho ManageEngine Remote Access Plus?
CVE-2019-11361 affects Zoho ManageEngine Remote Access Plus version 10.0.258 by not properly validating user permissions, leading to privilege escalation and a potential full application takeover.
How can privilege escalation occur in Zoho ManageEngine Remote Access Plus due to CVE-2019-11361?
Privilege escalation can occur in Zoho ManageEngine Remote Access Plus due to CVE-2019-11361 because the vulnerability allows an attacker to elevate their privileges and gain unauthorized access to sensitive resources.
Is there a fix available for CVE-2019-11361 in Zoho ManageEngine Remote Access Plus?
Yes, a fix is available for CVE-2019-11361 in Zoho ManageEngine Remote Access Plus. It is recommended to update to a version that properly validates user permissions.
Where can I find more information about CVE-2019-11361 in Zoho ManageEngine Remote Access Plus?
More information about CVE-2019-11361 in Zoho ManageEngine Remote Access Plus can be found at the following link: [https://www.manageengine.com/remote-desktop-management/knowledge-base/elevation-of-privilege.html]