VYPR
patchPublished Sep 23, 2026· 1 source

Critical ManageEngine Flaw Allows SYSTEM Access via Windows Login Screen

A critical vulnerability in ManageEngine ADSelfService Plus allows unauthenticated attackers to gain SYSTEM-level code execution through the Windows login screen.

ManageEngine has released a patch for CVE-2026-74849, a critical remote code execution (RCE) vulnerability affecting its ADSelfService Plus product. The flaw resides within the product's GINA client, a component that integrates password reset and account unlock functionalities directly onto the Windows login screen. This allows users to perform these actions without needing to reach the full Windows desktop.

The vulnerability, identified as CWE-78 (OS command injection), enables unauthenticated attackers who can access the Windows login screen to execute arbitrary code with SYSTEM privileges. SYSTEM is one of the most powerful local accounts on Windows, granting attackers the ability to modify protected files, create or alter user accounts, install services, disable security software, access sensitive local data, and establish persistent control over the affected endpoint.

According to ManageEngine's advisory, exploitation requires access to the Windows login screen. However, given the elevated privileges and pre-authentication nature of login screen software, any successful compromise could lead to complete control of a workstation or server. The vulnerability has been assigned a CVSS v3.1 score of 9.8, classifying it as Critical.

CVE-2026-74849 specifically impacts ManageEngine ADSelfService Plus builds 7000 and earlier. The company has addressed the issue in build 7001, released on August 24, 2026. The update includes corrections to error handling and strengthens the security of the embedded browser component exposed at the login screen.

Security teams are urged to identify all endpoints utilizing the ADSelfService Plus GINA client and verify their installed build. Any instance running below build 7001 must be updated immediately via the ADSelfService Plus service pack process. Administrators should also conduct thorough log reviews for any signs of suspicious activity, such as unexpected processes, unusual command executions, new service installations, or modifications to local administrator accounts, particularly around the time of login screen usage.

While an immediate update is the most effective remediation, organizations unable to patch right away should implement mitigating measures. These include limiting physical and remote access to affected Windows login screens, restricting the exposure of the GINA-related service to untrusted networks, and closely monitoring the behavior of the affected hosts. These steps can reduce the attack surface but do not eliminate the risk entirely.

The vulnerability was reported by Marouane Belabbassi and Amjad E Alhejaili through the Zoho BugBounty program. The critical nature of this flaw, offering a direct path to SYSTEM-level code execution, underscores the importance of prompt patching to protect endpoints from compromise.

Synthesized by Vypr AI
Critical ManageEngine Flaw Allows SYSTEM Access via Windows Login Screen · VYPR