Medium severity6.4NVD Advisory· Published Mar 23, 2020· Updated Jun 17, 2026
CVE-2020-8838
CVE-2020-8838
Description
An issue was discovered in Zoho ManageEngine AssetExplorer 6.5. During an upgrade of the Windows agent, it does not validate the source and binary downloaded. This allows an attacker on an adjacent network to execute code with NT AUTHORITY/SYSTEM privileges on the agent machines by providing an arbitrary executable via a man-in-the-middle attack.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:zohocorp:manageengine_assetexplorer:6.5:*:*:*:*:*:*:*
- Zoho/ManageEngine AssetExplorerdescription
- Range: 6.5
Patches
Vulnerability mechanics
References
3- packetstormsecurity.com/files/157612/ManageEngine-Asset-Explorer-Windows-Agent-Remote-Code-Execution.htmlnvdExploitThird Party AdvisoryVDB Entry
- seclists.org/fulldisclosure/2020/May/29nvdExploitMailing ListThird Party Advisory
- www.manageengine.com/products/asset-explorer/sp-readme.htmlnvdRelease NotesVendor Advisory
News mentions
0No linked articles in our index yet.