Skip to content
COOEY

EXPOSURES › CVE-2021-44515

CVE-2021-44515

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-12-10 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-44515 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 75/100 rceexploited-in-wildunpatchedauth-bypass

Zoho Desktop Central had an authentication bypass vulnerability allowing arbitrary code execution on the MSP server.

An authentication bypass in Zoho Desktop Central allowed attackers to execute arbitrary code on the MSP server, representing a critical security failure. DIB organizations must ensure their MSP tools are patched and monitored for such vulnerabilities to prevent unauthorized access and data compromise. This failure highlights the risk of relying on vendors with a history of unpatched critical vulnerabilities.

Shame score — The vulnerability allowed arbitrary code execution via an authentication bypass, and Zoho has a documented history of similar critical and high-severity RCE vulnerabilities across its product line.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Zoho Desktop Central contains an authentication bypass vulnerability that could allow an attacker to execute arbitrary code in the Desktop Central MSP server.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.