ZDI-23-1488: ManageEngine ADManager Plus installServiceWithCredentials Command Injection Remote Code Execution Vulnerability
Published Sep 29, 2023
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of ManageEngine ADManager Plus. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2023-38743.
Affected Software
1 affected component
ManageEngine ADManager Plus
Event History
Sep 29, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-23-1488?
The severity of ZDI-23-1488 is rated at 7.2, indicating a high risk level.
2
How do I fix ZDI-23-1488?
To fix ZDI-23-1488, apply the latest security patches provided by ManageEngine for ADManager Plus.
3
What type of attacks can be executed through ZDI-23-1488?
ZDI-23-1488 allows remote attackers to execute arbitrary code on affected installations.
4
Is authentication required to exploit ZDI-23-1488?
Yes, authentication is required to exploit the ZDI-23-1488 vulnerability.
5
Which software is affected by ZDI-23-1488?
ZDI-23-1488 affects ManageEngine ADManager Plus installations.