CVE-2021-44757: Critical severity manageengine desktop central vulnerability
Zoho ManageEngine Desktop Central before 10.1.2137.9 and Desktop Central MSP before 10.1.2137.9 allow attackers to bypass authentication, and read sensitive information or upload an arbitrary ZIP archive to the server.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-44757?
CVE-2021-44757 refers to a vulnerability in Zoho ManageEngine Desktop Central and Desktop Central MSP that allows attackers to bypass authentication and perform unauthorized actions.
What is the severity of CVE-2021-44757?
The severity of CVE-2021-44757 is critical with a CVSS score of 9.1.
How does CVE-2021-44757 affect Zoho ManageEngine Desktop Central and Desktop Central MSP?
CVE-2021-44757 allows attackers to bypass authentication, read sensitive information, or upload an arbitrary ZIP archive to the server in Zoho ManageEngine Desktop Central and Desktop Central MSP versions before 10.1.2137.9.
How can I fix CVE-2021-44757?
To fix CVE-2021-44757, you should update Zoho ManageEngine Desktop Central and Desktop Central MSP to version 10.1.2137.9 or above.
Where can I find more information about CVE-2021-44757?
More information about CVE-2021-44757 can be found at the following URL: https://pitstop.manageengine.com/portal/en/community/topic/a-critical-security-patch-released-in-desktop-central-and-desktop-central-msp-for-cve-2021-44757-17-1-2022