Skip to content
COOEY

EXPOSURES › CVE-2018-5353

CVE-2018-5353

CRITICAL
DETAIL
SourceNVD · cve Published2020-09-30 CVSS9.8 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2018-5353 ↗
SHAME 35/100

The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execute code and escalate privileges via spoofing. It does not authenticate the intended server before opening a browser window. An unauthenticated attacker capable

▸ RECOMMENDED ACTION  Critical severity — schedule patching of the affected products.

DESCRIPTION

The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execute code and escalate privileges via spoofing. It does not authenticate the intended server before opening a browser window. An unauthenticated attacker capable of conducting a spoofing attack can redirect the browser to gain execution in the context of the WinLogon.exe process. If Network Level Authentication is not enforced, the vulnerability can be exploited via RDP. Additionally, if the web server has a misconfigured certificate then no spoofing attack is required

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.80
CVE-2018-5353 represents a critical remote code execution vulnerability in Zoho ManageEngine ADSelfService Plus, allowing privilege escalation via spoofing without proper server authentication. The vu
cooey ↗ severe-fallout -0.90
Critical vulnerability disclosure
"The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execute code and escalate privileges via spoofing."
www.cvefind.com ↗ severe-fallout +0.00
Neutral database listing
app.opencve.io ↗ severe-fallout +0.00
Neutral database listing
chromereleases.googleblog.com ↗ severe-fallout +0.00
Neutral database listing
www.iheart.com ↗ severe-fallout +0.00
Neutral database listing
www.idtheftcenter.org ↗ severe-fallout +0.00
Neutral database listing
classactionu.org ↗ severe-fallout +0.00
Neutral database listing
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.