First published: Tue Jan 18 2022(Updated: )
Zoho ManageEngine Desktop Central before 10.1.2137.9 and Desktop Central MSP before 10.1.2137.9 allow attackers to bypass authentication, and read sensitive information or upload an arbitrary ZIP archive to the server.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zohocorp Manageengine Desktop Central | <10.1.2137.9 | |
Zohocorp Manageengine Desktop Central Managed Service Providers | <10.1.2137.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-44757 refers to a vulnerability in Zoho ManageEngine Desktop Central and Desktop Central MSP that allows attackers to bypass authentication and perform unauthorized actions.
The severity of CVE-2021-44757 is critical with a CVSS score of 9.1.
CVE-2021-44757 allows attackers to bypass authentication, read sensitive information, or upload an arbitrary ZIP archive to the server in Zoho ManageEngine Desktop Central and Desktop Central MSP versions before 10.1.2137.9.
To fix CVE-2021-44757, you should update Zoho ManageEngine Desktop Central and Desktop Central MSP to version 10.1.2137.9 or above.
More information about CVE-2021-44757 can be found at the following URL: https://pitstop.manageengine.com/portal/en/community/topic/a-critical-security-patch-released-in-desktop-central-and-desktop-central-msp-for-cve-2021-44757-17-1-2022