EXPOSURES › CVE-2020-10189
CVE-2020-10189
HIGH ⌖ ON CISA KEV · EXPLOITEDUnauthenticated remote code execution via file upload in Zoho ManageEngine Desktop Central.
An unauthenticated file upload vulnerability in Zoho ManageEngine Desktop Central allowed attackers to execute arbitrary code remotely. This is a critical failure for DIB organizations because it enables remote code execution (RCE) without authentication, directly violating CMMC/NIST 800-171 requirements for access control and system integrity. Organizations must ensure all ManageEngine products are patched immediately and assess their exposure to similar unpatched RCE flaws.
Shame score — The vulnerability allowed unauthenticated remote code execution, a severe flaw that was actively exploited in the wild (KEV) and reflects a pattern of unpatched critical RCE issues in the vendor's product line.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Zoho ManageEngine Desktop Central contains a file upload vulnerability that allows for unauthenticated remote code execution.