Zoho ManageEngine OpManager Insecure Deserialization Leading to RCE

Strike ID:
E25-gnob1
CVSS:
8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
False Positive:
f
Variants:
1
Year:
2023

Description

This strike exploits an insecure deserialization vulnerability in Zoho ManageEngine OpManager. The vulnerability exists due to insufficient validation of serialized objects in the communication between central and probe servers. A remote, authenticated attacker could leverage this flaw by sending a crafted request, leading to arbitrary code execution with SYSTEM privileges.

CVE

References