CVE-2021-42954: High severity zoho manageengine remote access plus vulnerability
Zoho Remote Access Plus Server Windows Desktop Binary fixed from 10.1.2121.1 is affected by incorrect access control. The installation directory is vulnerable to weak file permissions by allowing full control for Windows Everyone user group (non-admin or any guest users), thereby allowing privilege escalation, unauthorized password reset, stealing of sensitive data, access to credentials in plaintext, access to registry values, tampering with configuration files, etc.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for Zoho Remote Access Plus Server Windows Desktop Binary?
The vulnerability ID for Zoho Remote Access Plus Server Windows Desktop Binary is CVE-2021-42954.
What is the severity of CVE-2021-42954?
The severity of CVE-2021-42954 is high, with a severity value of 7.8.
What is the affected software for CVE-2021-42954?
The affected software for CVE-2021-42954 is Zohocorp Manageengine Remote Access Plus, version up to 10.1.2121.1.
What is the description of CVE-2021-42954?
CVE-2021-42954 is a vulnerability in Zoho Remote Access Plus Server Windows Desktop Binary that allows incorrect access control, specifically weak file permissions.
How can I fix CVE-2021-42954?
To fix CVE-2021-42954, update Zoho Remote Access Plus Server Windows Desktop Binary to version 10.1.2121.1 or later.