9.8

CVE-2018-5353

Exploit
The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execute code and escalate privileges via spoofing. It does not authenticate the intended server before opening a browser window. An unauthenticated attacker capable of conducting a spoofing attack can redirect the browser to gain execution in the context of the WinLogon.exe process. If Network Level Authentication is not enforced, the vulnerability can be exploited via RDP. Additionally, if the web server has a misconfigured certificate then no spoofing attack is required
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zohocorp ≫ Manageengine Adselfservice Plus Version 5.5 Update -
Zohocorp ≫ Manageengine Adselfservice Plus Version 5.5 Update 5500
Zohocorp ≫ Manageengine Adselfservice Plus Version 5.5 Update 5501
Zohocorp ≫ Manageengine Adselfservice Plus Version 5.5 Update 5502
Zohocorp ≫ Manageengine Adselfservice Plus Version 5.5 Update 5503
Zohocorp ≫ Manageengine Adselfservice Plus Version 5.5 Update 5504
Zohocorp ≫ Manageengine Adselfservice Plus Version 5.5 Update 5505
Zohocorp ≫ Manageengine Adselfservice Plus Version 5.5 Update 5506
Zohocorp ≫ Manageengine Adselfservice Plus Version 5.5 Update 5507
Zohocorp ≫ Manageengine Adselfservice Plus Version 5.5 Update 5508
Zohocorp ≫ Manageengine Adselfservice Plus Version 5.5 Update 5509
Zohocorp ≫ Manageengine Adselfservice Plus Version 5.5 Update 5510
Zohocorp ≫ Manageengine Adselfservice Plus Version 5.5 Update 5511
Zohocorp ≫ Manageengine Adselfservice Plus Version 5.5 Update 5512
Zohocorp ≫ Manageengine Adselfservice Plus Version 5.5 Update 5513
Zohocorp ≫ Manageengine Adselfservice Plus Version 5.5 Update 5514
Zohocorp ≫ Manageengine Adselfservice Plus Version 5.5 Update 5515
Zohocorp ≫ Manageengine Adselfservice Plus Version 5.5 Update 5516
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 11.06% 0.954
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-290 Authentication Bypass by Spoofing

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

https://www.manageengine.com/products/self-service-password/release-notes.html
Vendor Advisory
Release Notes
https://github.com/missing0x00/CVE-2018-5353
Third Party Advisory
Exploit