HomeSecurityZoho fixes exploitable flaw in ADSelfService Plus

Zoho fixes exploitable flaw in ADSelfService Plus

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning that malicious actors are exploiting a critical vulnerability in ADSelfService Plus , which allows them to take control of the system.

ADSelfService Plus

See also: New DNS vulnerability allows for 'state-level espionage'

ADSelfService Plus is aimed at larger organizations that need a comprehensive self-service password management and login solution for Active Directory and cloud applications.

The security issue, dubbed CVE-2021-40539, is considered critical as it could allow a remote, unauthenticated attacker to execute arbitrary code on a vulnerable system.

Zoho published an announcement announcing the release of an update that fixes the bug in ADSelfService Plus.

In a weekly security alert, the company said it has “discovered indications that this vulnerability is being exploited” by malicious actors online.

See also: Hackers target their victims' internet connections

The notice from CISA clearly refers to this vulnerability, as the organization informs that “CVE-2021-40539 has been identified in online exploits.”

At this time, information about the vulnerability is scarce. A severity rating has not been calculated by the National Institute of Standards and Technology in the US, but Zoho notes that the issue is critical:

“An authentication bypass vulnerability affecting REST API URLs, which could lead to remote code execution,” the company describes it.

Zoho error

Organizations with ADSelfService Plus structures older than 6114 are urged to apply the latest update from the developer, using the service pack.

See also: New Hog ransomware decrypts victims' files only if they connect to its developer's Discord server

CVE-2021-40539 is the fifth critical vulnerability reported for Zoho ManageEngine ADSelfService Plus this year. The previous four are:

CVE-2021-37421- Admin portal access bypass. Bypass in Zoho ManageEngine ADSelfService Plus 6103 and later

CVE-2021-37417- CAPTCHA bypass due to improper parameter validation in Zoho ManageEngine ADSelfService Plus build 6103 and earlier

CVE-2021-33055- unauthenticated remote code execution in non-English versions affecting Zoho ManageEngine ADSelfService Plus up to 6102

CVE-2021-28958- unauthenticated remote code execution while changing password in all Zoho ManageEngine ADSelfService Plus up to 6101

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS