EXPOSURES › CVE-2021-44077
CVE-2021-44077
HIGH ⌖ ON CISA KEV · EXPLOITEDUnauthenticated remote code execution in Zoho ManageEngine ServiceDesk Plus allowed attackers to execute arbitrary code on vulnerable systems.
The vulnerability (CVE-2021-44077) allowed unauthenticated remote code execution in Zoho ManageEngine ServiceDesk Plus and SupportCenter Plus before specific versions. DIB organizations must ensure these products are patched to prevent attackers from gaining full system control, which could lead to data breaches, ransomware deployment, or lateral movement. Organizations should verify their versions and apply the latest patches immediately.
Shame score — An unauthenticated RCE in a widely deployed IT service management tool is highly avoidable and represents a severe negligence failure, especially given its inclusion in CISA's KEV catalog.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution