Critical severity9.8CISA KEVNVD Advisory· Published Mar 6, 2020· Updated Jun 17, 2026
CVE-2020-10189
CVE-2020-10189
Description
Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImage in the FileStorage class. This is related to the CewolfServlet and MDMLogUploaderServlet servlets.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- cpe:2.3:a:zohocorp:manageengine_desktop_central:*:*:*:*:*:*:*:*Range: <10.0.479
- Zoho/ManageEngine Desktop Centraldescription
- Range: <10.0.474
- Range: <10.0.474
Patches
Vulnerability mechanics
References
7- packetstormsecurity.com/files/156730/ManageEngine-Desktop-Central-Java-Deserialization.htmlnvdExploitThird Party AdvisoryVDB Entry
- srcincite.io/advisories/src-2020-0011/nvdExploitThird Party Advisory
- srcincite.io/pocs/src-2020-0011.py.txtnvdExploitThird Party Advisory
- cwe.mitre.org/data/definitions/502.htmlnvdThird Party Advisory
- www.manageengine.com/products/desktop-central/remote-code-execution-vulnerability.htmlnvdVendor Advisory
- www.zdnet.com/article/zoho-zero-day-published-on-twitter/nvdThird Party Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
0No linked articles in our index yet.