CVE-2019-19034: OS Command Injection
Zoho ManageEngine Asset Explorer 6.5 does not validate the System Center Configuration Manager (SCCM) database username when dynamically generating a command to schedule scans for SCCM. This allows an attacker to execute arbitrary commands on the AssetExplorer Server with NT AUTHORITY/SYSTEM privileges.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-19034?
CVE-2019-19034 is a vulnerability in Zoho ManageEngine Asset Explorer 6.5 that allows an attacker to execute arbitrary commands on the AssetExplorer Server with NT AUTHORITY/SYSTEM privileges.
How severe is CVE-2019-19034?
CVE-2019-19034 has a severity rating of 7.2 (high).
How does CVE-2019-19034 work?
CVE-2019-19034 occurs due to a lack of validation in the System Center Configuration Manager (SCCM) database username when scheduling scans for SCCM. This allows an attacker to execute arbitrary commands.
Which version of Zoho ManageEngine Asset Explorer is affected?
Zoho ManageEngine Asset Explorer 6.5 is affected by CVE-2019-19034.
Is there a fix available for CVE-2019-19034?
Yes, it is recommended to update to the latest version of Zoho ManageEngine Asset Explorer to fix CVE-2019-19034.