CVE-2018-13411
Description
An issue was discovered in Zoho ManageEngine Desktop Central before 10.0.282. A clickable company logo in a window running as SYSTEM can be abused to escalate privileges. In cloud, the issue is fixed in 10.0.470 agent version.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A clickable logo in Zoho ManageEngine Desktop Central agent running as SYSTEM allows local privilege escalation to SYSTEM.
Vulnerability
An issue in Zoho ManageEngine Desktop Central before version 10.0.282 (and cloud agent before 10.0.470) allows local privilege escalation. The Self Service Portal window, which runs with SYSTEM privileges, contains a clickable ManageEngine logo. When clicked, this logo opens a web browser also running as SYSTEM, providing a vector for privilege escalation [1][2].
Exploitation
An attacker with local access to a machine where the Desktop Central Agent is installed can trigger the vulnerability. First, execute C:\Program Files (x86)\DesktopCentral_Agent\bin\dcagenttrayicon.exe -ssp to open the Self Service Portal window as SYSTEM. Then, click the ManageEngine logo in that window, which opens a web browser with SYSTEM privileges. From the browser, the attacker can launch cmd.exe or PowerShell.exe to obtain a SYSTEM command prompt [1].
Impact
Successful exploitation grants the attacker a command prompt running with SYSTEM privileges, resulting in full compromise of the affected machine. The attacker gains complete control over the system, including the ability to install programs, modify data, and create new accounts [1][2].
Mitigation
The vulnerability is fixed in Desktop Central version 10.0.282 (on-premises) and agent version 10.0.470 (cloud), released on August 23, 2018. Administrators should log in to the Desktop Central console, click the current build number, download the applicable PPM, and apply the update. No workaround is documented [2].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: <10.0.282
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.securityfocus.com/bid/105348mitrevdb-entryx_refsource_BID
- github.com/AJ-SA/Zoho-ManageEngine/blob/master/README.mdmitrex_refsource_MISC
- www.manageengine.com/products/desktop-central/elevation-of-system-privilege.htmlmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.