CVE-2021-37921: Malicious File Upload
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Zoho ManageEngine ADManager Plusto a version that resolves this vulnerability.Fixed in 7110 - Compensating control
Mitigate while patching by restricting/unblocking the affected file upload functionality from untrusted sources (e.g., limit access to the ADManager Plus web UI/file upload endpoints to trusted IPs via firewall/reverse proxy/ACL).
Event History
Frequently Asked Questions
What is CVE-2021-37921?
CVE-2021-37921 is a vulnerability in Zoho ManageEngine ADManager Plus version 7110 and prior that allows unrestricted file upload, leading to remote code execution.
What is the severity level of CVE-2021-37921?
CVE-2021-37921 has a severity level of 9.8 (critical).
How does CVE-2021-37921 affect Zoho ManageEngine ADManager Plus?
CVE-2021-37921 affects Zoho ManageEngine ADManager Plus version 7110 and prior, allowing unrestricted file upload and leading to remote code execution.
How can I fix the CVE-2021-37921 vulnerability?
To fix the CVE-2021-37921 vulnerability, you should update Zoho ManageEngine ADManager Plus to version 7.1-7111 or later.
Where can I find more information about CVE-2021-37921?
You can find more information about CVE-2021-37921 on the Zoho ManageEngine website and the ADManager Plus release notes.