Unrated severityNVD Advisory· Published Mar 23, 2020· Updated Aug 4, 2024
CVE-2020-8838
CVE-2020-8838
Description
An issue was discovered in Zoho ManageEngine AssetExplorer 6.5. During an upgrade of the Windows agent, it does not validate the source and binary downloaded. This allows an attacker on an adjacent network to execute code with NT AUTHORITY/SYSTEM privileges on the agent machines by providing an arbitrary executable via a man-in-the-middle attack.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Zoho/ManageEngine AssetExplorerdescription
- Range: =6.5 (as stated)
Patches
Vulnerability mechanics
References
3- packetstormsecurity.com/files/157612/ManageEngine-Asset-Explorer-Windows-Agent-Remote-Code-Execution.htmlmitrex_refsource_MISC
- seclists.org/fulldisclosure/2020/May/29mitremailing-listx_refsource_FULLDISC
- www.manageengine.com/products/asset-explorer/sp-readme.htmlmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.