CVE-2019-11361
Description
Zoho ManageEngine Remote Access Plus 10.0.258 does not validate user permissions properly, allowing for privilege escalation and eventually a full application takeover.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Zoho ManageEngine Remote Access Plus 10.0.258 before build 100454 allows guest users to perform privileged operations, leading to privilege escalation and full application compromise.
Vulnerability
A privilege escalation vulnerability exists in Zoho ManageEngine Remote Access Plus prior to build 100454 (version 10.0.258). The application fails to properly validate user permissions, allowing an unauthenticated or low-privileged user (e.g., a Guest user) to perform operations that should require administrative privileges [1].
Exploitation
An attacker with network access to the Remote Access Plus web console can exploit this vulnerability by sending crafted requests that impersonate an administrator. No special authentication or user interaction is required beyond having Guest-level access to the application [1].
Impact
Successful exploitation allows an attacker to escalate privileges to that of an administrator, potentially leading to full application takeover, including the ability to execute arbitrary code, access sensitive data, and modify system configurations [1].
Mitigation
The issue is resolved in Remote Access Plus build 100454, released on 17-March-2020. Users should download and apply the latest PPM (Patch Package Manager) from the product's service packs page. The vulnerability does not affect the cloud version of the product [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Zoho/ManageEngine Remote Access Plusdescription
- Range: =10.0.258
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.manageengine.com/remote-desktop-management/knowledge-base/elevation-of-privilege.htmlmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.