An elevation of privilege vulnerability exists in ManageEngine ADSelfService Plus before build 6003 because it does not properly enforce user privileges associated with a Certificate dialog
Published Aug 11, 2020
9.8
CRITICALCVSS 3.1
EPSS 7.40%
Description
An elevation of privilege vulnerability exists in ManageEngine ADSelfService Plus before build 6003 because it does not properly enforce user privileges associated with a Certificate dialog. This vulnerability could allow an unauthenticated attacker to escalate privileges on a Windows host. An attacker does not require any privilege on the target system in order to exploit this vulnerability. One option is the self-service option on the Windows login screen. Upon selecting this option, the thick-client software is launched, which connects to a remote ADSelfService Plus server to facilitate self-service operations. An unauthenticated attacker having physical access to the host could trigger a security alert by supplying a self-signed SSL certificate to the client. The View Certificate option from the security alert allows an attacker to export a displayed certificate to a file. This can further cascade to a dialog that can open Explorer as SYSTEM. By navigating from Explorer to \windows\system32, cmd.exe can be launched as a SYSTEM.
Affected products
No data.
- ≤ 5.8
- 6.0
- 6.0
- 6.0
- 6.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (7)
- http://packetstormsecurity.com/files/158820/ManageEngine-ADSelfService-Plus-6000-Remote-Code-Execution.html x_refsource_MISCExploitThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2020/Aug/4 x_refsource_MISCExploitMailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2020/Aug/6 mailing-listx_refsource_FULLDISCExploitMailing ListThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-3903 Advisory
- https://pitstop.manageengine.com/portal/en/community/topic/adselfservice-plus-6003-release-faceid-support x_refsource_CONFIRMRelease NotesVendor Advisory
- https://www.exploit-db.com/exploits/48739 x_refsource_MISCExploitThird Party AdvisoryVDB Entry
- https://www.manageengine.com x_refsource_MISCVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://packetstormsecurity.com/files/158820/ManageEngine-ADSelfService-Plus-6000-Remote-Code-Execution.html | x_refsource_MISCExploitThird Party AdvisoryVDB Entry | |
| http://seclists.org/fulldisclosure/2020/Aug/4 | x_refsource_MISCExploitMailing ListThird Party Advisory | |
| http://seclists.org/fulldisclosure/2020/Aug/6 | mailing-listx_refsource_FULLDISCExploitMailing ListThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-3903 | Advisory | |
| https://pitstop.manageengine.com/portal/en/community/topic/adselfservice-plus-6003-release-faceid-support | x_refsource_CONFIRMRelease NotesVendor Advisory | |
| https://www.exploit-db.com/exploits/48739 | x_refsource_MISCExploitThird Party AdvisoryVDB Entry | |
| https://www.manageengine.com | x_refsource_MISCVendor Advisory |
Change history (0)
No recorded changes yet.