EXPOSURES › CVE-2021-44515
CVE-2021-44515
HIGH ⌖ ON CISA KEV · EXPLOITEDZoho Desktop Central had an authentication bypass vulnerability allowing arbitrary code execution on the MSP server.
An authentication bypass in Zoho Desktop Central allowed attackers to execute arbitrary code on the MSP server, representing a critical security failure. DIB organizations must ensure their MSP tools are patched and monitored for such vulnerabilities to prevent unauthorized access and data compromise. This failure highlights the risk of relying on vendors with a history of unpatched critical vulnerabilities.
Shame score — The vulnerability allowed arbitrary code execution via an authentication bypass, and Zoho has a documented history of similar critical and high-severity RCE vulnerabilities across its product line.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Zoho Desktop Central contains an authentication bypass vulnerability that could allow an attacker to execute arbitrary code in the Desktop Central MSP server.