First published: Sat Nov 12 2022(Updated: )
This vulnerability allows remote attackers to escalate privileges on affected installations of ManageEngine ServiceDesk Plus MSP. Authentication is required to exploit this vulnerability. The specific flaw exists within the exportMickeyList action. The issue results from the lack of proper validation of user-supplied data. An attacker can leverage this vulnerability to escalate privileges to resources normally protected from the user.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus | <10.6 | |
Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus | =10.6 | |
Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus | =10.6-10600 | |
Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus | =10.6-10601 | |
Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus | =10.6-10602 | |
Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus | =10.6-10603 | |
Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus | =10.6-10604 | |
Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus | =10.6-10605 | |
Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus | =10.6-10606 | |
Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus | =10.6-10607 | |
Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus | =10.6-10608 | |
Zohocorp Manageengine Supportcenter Plus | <11.0 | |
Zohocorp Manageengine Supportcenter Plus | =11.0 | |
Zohocorp Manageengine Supportcenter Plus | =11.0-11000 | |
Zohocorp Manageengine Supportcenter Plus | =11.0-11001 | |
Zohocorp Manageengine Supportcenter Plus | =11.0-11002 | |
Zohocorp Manageengine Supportcenter Plus | =11.0-11003 | |
Zohocorp Manageengine Supportcenter Plus | =11.0-11004 | |
Zohocorp Manageengine Supportcenter Plus | =11.0-11005 | |
Zohocorp Manageengine Supportcenter Plus | =11.0-11006 | |
Zohocorp Manageengine Supportcenter Plus | =11.0-11007 | |
Zohocorp Manageengine Supportcenter Plus | =11.0-11008 | |
Zohocorp Manageengine Supportcenter Plus | =11.0-11009 | |
Zohocorp Manageengine Supportcenter Plus | =11.0-11010 | |
Zohocorp Manageengine Supportcenter Plus | =11.0-11011 | |
Zohocorp Manageengine Supportcenter Plus | =11.0-11012 | |
Zohocorp Manageengine Supportcenter Plus | =11.0-11013 | |
Zohocorp Manageengine Supportcenter Plus | =11.0-11014 | |
Zohocorp Manageengine Supportcenter Plus | =11.0-11015 | |
Zohocorp Manageengine Supportcenter Plus | =11.0-11016 | |
Zohocorp Manageengine Supportcenter Plus | =11.0-11017 | |
Zohocorp Manageengine Supportcenter Plus | =11.0-11018 | |
Zohocorp Manageengine Supportcenter Plus | =11.0-11019 | |
Zohocorp Manageengine Supportcenter Plus | =11.0-11020 | |
Zohocorp Manageengine Supportcenter Plus | =11.0-11021 | |
Zohocorp Manageengine Supportcenter Plus | =11.0-11022 | |
Zohocorp Manageengine Supportcenter Plus | =11.0-11024 | |
ManageEngine ServiceDesk Plus MSP |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-40773 is a vulnerability that allows remote attackers to escalate privileges on affected installations of ManageEngine ServiceDesk Plus MSP.
Yes, authentication is required to exploit CVE-2022-40773.
CVE-2022-40773 has a severity rating of 8.8 (high).
To fix CVE-2022-40773, users should update to a patched version of ManageEngine ServiceDesk Plus MSP or apply the necessary security updates.
More information about CVE-2022-40773 can be found on the official ManageEngine website and the Zero Day Initiative advisory page.