Rewterz Threat Alert – CrySIS aka Dharma Ransomware – Active IOCs
January 18, 2022Rewterz Threat Alert – AZORult Malware – Active IOCs
January 18, 2022Rewterz Threat Alert – CrySIS aka Dharma Ransomware – Active IOCs
January 18, 2022Rewterz Threat Alert – AZORult Malware – Active IOCs
January 18, 2022Severity
High
Analysis Summary
CVE-2021-44757
Zoho ManageEngine Desktop Central and Desktop Central MSP could allow a remote attacker to bypass security restrictions, caused by improper authentication validation. By sending a specially-crafted request, an attacker could exploit this vulnerability to read unauthorized data or write an arbitrary zip file on the server.
The company recommends customers to follow the security hardening guidelines for Desktop Central and Desktop Central MSP to secure their installs.
Impact
- Bypass Security
Affected Vendors
- Zoho
Affected Products
- ManageEngine Desktop Central
- Zoho ManageEngine Desktop Central MSP
Remediation
For patches, upgrades or suggested workaround information, refer to the following: