CVE-2021-37924: Malicious File Upload
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Zoho ManageEngine ADManager Plusto a version that resolves this vulnerability.Fixed in 7110 - Compensating control
Mitigate the unrestricted file upload that can lead to remote code execution by restricting access to the ADManager Plus application endpoints (e.g., via network ACL/firewall) until the product is patched.
Event History
Frequently Asked Questions
What is CVE-2021-37924?
CVE-2021-37924 is a vulnerability in Zoho ManageEngine ADManager Plus version 7110 and prior that allows unrestricted file upload, leading to remote code execution.
What is the severity of CVE-2021-37924?
The severity of CVE-2021-37924 is critical with a CVSS score of 9.8.
How does CVE-2021-37924 affect Zoho ManageEngine ADManager Plus?
CVE-2021-37924 affects Zoho ManageEngine ADManager Plus version 7110 and prior, allowing unrestricted file upload which can lead to remote code execution.
Is there a fix for CVE-2021-37924?
Yes, the fix for CVE-2021-37924 is to upgrade to a version of Zoho ManageEngine ADManager Plus that is higher than 7110.
Where can I find more information about CVE-2021-37924?
You can find more information about CVE-2021-37924 on the Zoho ManageEngine website and in the release notes for ADManager Plus.