Korean
<< Back
VID 210194
Severity 40
Port 80, ...
Protocol TCP
Class WWW
Detailed Description Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImage in the FileStorage class. This is related to the CewolfServlet and MDMLogUploaderServlet servlets.

* References:
https://github.com/zavke/CVE-2020-10189-ManageEngine/blob/main/src-2020-0011.py
http://packetstormsecurity.com/files/156730/ManageEngine-Desktop-Central-Java-Deserialization.html
https://srcincite.io/advisories/src-2020-0011/
https://srcincite.io/pocs/src-2020-0011.py.txt
https://www.manageengine.com/products/desktop-central/remote-code-execution-vulnerability.html
https://www.zdnet.com/article/zoho-zero-day-published-on-twitter/

* Platforms Affected:
Zoho ManageEngine Desktop Central 10.0.474 before
Recommendation Upgrade Zoho ManageEngine Desktop Central 10.0.474 later
Related URL CVE-2020-10189 (CVE)
Related URL (SecurityFocus)
Related URL (ISS)