First published: Sat Feb 25 2023(Updated: )
Zoho ManageEngine Desktop Central and Desktop Central MSP before 10.1.2137.2 allow directory traversal via computerName to AgentLogUploadServlet. A remote, authenticated attacker could upload arbitrary code that would be executed when Desktop Central is restarted. (The attacker could authenticate by exploiting CVE-2021-44515.)
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zohocorp Manageengine Desktop Central | <10.1.2137.2 | |
Zohocorp Manageengine Desktop Central | <10.1.2137.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-48362 is a vulnerability in Zoho ManageEngine Desktop Central and Desktop Central MSP before version 10.1.2137.2 that allows directory traversal and arbitrary code execution.
CVE-2022-48362 has a severity score of 8.8 (high).
CVE-2022-48362 works by exploiting the directory traversal vulnerability in the computerName parameter of the AgentLogUploadServlet, allowing a remote, authenticated attacker to upload arbitrary code that will be executed when Desktop Central is restarted.
Zoho ManageEngine Desktop Central and Desktop Central MSP versions up to and excluding 10.1.2137.2 are affected by CVE-2022-48362.
To fix CVE-2022-48362, users should upgrade to version 10.1.2137.2 or later of Zoho ManageEngine Desktop Central and Desktop Central MSP.