VYPR
Unrated severityNVD Advisory· Published Jan 12, 2022· Updated Aug 4, 2024

CVE-2021-44650

CVE-2021-44650

Description

Zoho ManageEngine M365 Manager Plus before Build 4419 allows remote command execution when updating proxy settings through the Admin ProxySettings and Tenant ProxySettings components.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Zoho ManageEngine M365 Manager Plus before Build 4419 allows remote command execution via crafted proxy settings.

Vulnerability

A remote command execution vulnerability exists in Zoho ManageEngine M365 Manager Plus prior to Build 4419. The flaw resides in the Admin ProxySettings and Tenant ProxySettings components, where user-supplied input is not properly sanitized when updating proxy configuration. An attacker can inject arbitrary operating system commands that are executed with the privileges of the application server. Affected versions are all builds before 4419 [1].

Exploitation

Exploitation requires an authenticated user with administrative privileges to access the proxy settings interface. The attacker crafts a malicious proxy hostname or port value containing command injection payloads. When the administrator saves the proxy settings, the injected commands are executed on the underlying server. No additional user interaction is needed beyond the initial authentication [1].

Impact

Successful exploitation results in remote code execution on the M365 Manager Plus server. The attacker gains the same privileges as the application process, typically SYSTEM or a high-privileged service account. This can lead to full compromise of the server, including data exfiltration, lateral movement, and further attacks within the network [1].

Mitigation

The vulnerability is fixed in Build 4419, released by Zoho ManageEngine. Users should upgrade to Build 4419 or later immediately. No workarounds are documented. The product is not listed on the CISA KEV as of the publication date [1].

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.