Several Zoho ManageEngine products have been exploited

Threat Level – Red | Vulnerability Report
Download PDF

For a detailed advisory, download the pdf file here.

Multiple vulnerabilities have been discovered in Zoho ManageEngine products. The affected products include Zoho ManageEngine ServiceDesk Plus, Zoho ManageEngine SupportCenter Plus, Zoho ManageEngine Desktop Central, Zoho ManageEngine AssetExplorer.CVE 2021 44077 is a vulnerability that could allow an attacker to run arbitrary code. It was discovered on November 20, 2021. This vulnerability, however, may be easily fixed by updating to Zoho version 11306, which was released in September. Attackers are focusing on the healthcare, financial services, electronics, and IT consulting businesses by exploiting this vulnerability.CVE 2021 44515 & CVE 2021 44526 are authentication bypass vulnerabilities. CVE 2021 44515 only affects Zoho ManageEngine ServiceDesk and Zoho ManageEngine AssetExplorer who uses Desktop Central Agent for asset discovery and CVE 2021 44526 affects all vulnerable versions of Zoho ManageEngine ServiceDesk and Zoho ManageEngine AssetExplorer.Two of these vulnerabilities (CVE 2021 44077 and CVE 2021 44515) have been exploited in the wild so organizations should upgrade their Zoho ManageEngine products to their latest versions to eliminate these vulnerabilities.The Techniques used by an unknown actor to exploit CVE 2021 44077 includes:T1190 – Exploit Public Facing ApplicationT1505.003 – Server Software Component: Web ShellT1027 – Obfuscated Files or InformationT1140 – Deobfuscate/Decode Files or InformationT1003 – OS Credential DumpingT1218 – Signed Binary Proxy ExecutionT1136 – Create AccountT1003.003 – OS Credential Dumping: NTDST1047 – Windows Management InstrumentationT1070.004 – Indicator Removal on Host: File DeletionT1087.002 – Account Discovery: Domain AccountT1560.001 – Archive Collected Data: Archive via UtilityT1573.001 – Encrypted Channel: Symmetric Cryptography

Vulnerability Details

Indicators of Compromise(IoCs) *

Patch Link

https://www.manageengine.com/desktop-management-msp/cve-2021-44515-security-advisory.html

https://www.manageengine.com/products/service-desk/security-response-plan.html

https://pitstop.manageengine.com/portal/en/community/topic/security-advisory-for-cve-2021-44526-and-cve-2021-44515-authentication-bypass-vulnerabilities-in-servicedesk-plus-and-desktop-central

https://pitstop.manageengine.com/portal/en/community/topic/security-advisory-for-cve-2021-44526-and-cve-2021-44515-authentication-bypass-vulnerabilities-in-assetexplorer-and-desktop-central

References

https://us-cert.cisa.gov/ncas/alerts/aa21-336a

https://www.bleepingcomputer.com/news/security/zoho-patch-new-manageengine-bug-exploited-in-attacks-asap/

https://unit42.paloaltonetworks.com/tiltedtemple-manageengine-servicedesk-plus/

 

 

* Indicates parameters that apply to CVE-2021-44077

What’s new on HivePro

Get through updates and upcoming events, and more directly in your inbox