CVE-2026-12267: Authenticated PowerShell Injection in DNS Query Resolution Policy leads to RCE
ManageEngine DDI Central versions below 6201 are vulnerable to Command injection in Windows DNS Query Resolution Policy name field leading to remote code execution.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ManageEngine DDI Centralto a version that resolves this vulnerability.Fixed in 6201
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs authenticated access with the high privileges required to create or modify a Windows DNS Query Resolution Policy. The attack can be performed remotely over the network and does not require user interaction.
Which deployments are affected?
ManageEngine DDI Central versions below 6201 are affected. The vulnerable input is the name field for Windows DNS Query Resolution Policy configuration.
What is the impact of successful exploitation?
Successful command injection can lead to remote code execution, with high impact to confidentiality, integrity, and availability.