First published: Sat Nov 12 2022(Updated: )
This vulnerability allows remote attackers to escalate privileges on affected installations of ManageEngine ServiceDesk Plus MSP. Authentication is required to exploit this vulnerability. The specific flaw exists within the exportMickeyList action. The issue results from the lack of proper validation of user-supplied data. An attacker can leverage this vulnerability to escalate privileges to resources normally protected from the user.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zoho ManageEngine ServiceDesk Plus MSP | ||
Zoho ManageEngine ServiceDesk Plus MSP | <10.6 | |
Zoho ManageEngine ServiceDesk Plus MSP | =10.6 | |
Zoho ManageEngine ServiceDesk Plus MSP | =10.6-10600 | |
Zoho ManageEngine ServiceDesk Plus MSP | =10.6-10601 | |
Zoho ManageEngine ServiceDesk Plus MSP | =10.6-10602 | |
Zoho ManageEngine ServiceDesk Plus MSP | =10.6-10603 | |
Zoho ManageEngine ServiceDesk Plus MSP | =10.6-10604 | |
Zoho ManageEngine ServiceDesk Plus MSP | =10.6-10605 | |
Zoho ManageEngine ServiceDesk Plus MSP | =10.6-10606 | |
Zoho ManageEngine ServiceDesk Plus MSP | =10.6-10607 | |
Zoho ManageEngine ServiceDesk Plus MSP | =10.6-10608 | |
ManageEngine SupportCenter Plus | <11.0 | |
ManageEngine SupportCenter Plus | =11.0 | |
ManageEngine SupportCenter Plus | =11.0-11000 | |
ManageEngine SupportCenter Plus | =11.0-11001 | |
ManageEngine SupportCenter Plus | =11.0-11002 | |
ManageEngine SupportCenter Plus | =11.0-11003 | |
ManageEngine SupportCenter Plus | =11.0-11004 | |
ManageEngine SupportCenter Plus | =11.0-11005 | |
ManageEngine SupportCenter Plus | =11.0-11006 | |
ManageEngine SupportCenter Plus | =11.0-11007 | |
ManageEngine SupportCenter Plus | =11.0-11008 | |
ManageEngine SupportCenter Plus | =11.0-11009 | |
ManageEngine SupportCenter Plus | =11.0-11010 | |
ManageEngine SupportCenter Plus | =11.0-11011 | |
ManageEngine SupportCenter Plus | =11.0-11012 | |
ManageEngine SupportCenter Plus | =11.0-11013 | |
ManageEngine SupportCenter Plus | =11.0-11014 | |
ManageEngine SupportCenter Plus | =11.0-11015 | |
ManageEngine SupportCenter Plus | =11.0-11016 | |
ManageEngine SupportCenter Plus | =11.0-11017 | |
ManageEngine SupportCenter Plus | =11.0-11018 | |
ManageEngine SupportCenter Plus | =11.0-11019 | |
ManageEngine SupportCenter Plus | =11.0-11020 | |
ManageEngine SupportCenter Plus | =11.0-11021 | |
ManageEngine SupportCenter Plus | =11.0-11022 | |
ManageEngine SupportCenter Plus | =11.0-11024 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-40773 is a vulnerability that allows remote attackers to escalate privileges on affected installations of ManageEngine ServiceDesk Plus MSP.
Yes, authentication is required to exploit CVE-2022-40773.
CVE-2022-40773 has a severity rating of 8.8 (high).
To fix CVE-2022-40773, users should update to a patched version of ManageEngine ServiceDesk Plus MSP or apply the necessary security updates.
More information about CVE-2022-40773 can be found on the official ManageEngine website and the Zero Day Initiative advisory page.