Later this week, a Proof-of-Concept for a serious vulnerability , allowing unauthenticated remote code execution in multiple VMware. This devastating security flaw allows hackers to gain unauthorized access to the system and cause massive destruction.
See also: Zoho urges admins to immediately fix a ManageEngine bug

CVE -2022-47966, is an RCE security vulnerability based on the use of a vulnerable and outdated third-party dependency of Apache Santuario.
RCE, or remote code execution, is a type of attack that allows an attacker to execute malicious code on a server, resulting in a complete compromise . This type of attack is possible when an application contains a vulnerability that the attacker can exploit. To successfully carry out an RCE attack, the attacker must first find a way to inject their malicious code into the vulnerable application. Once their code is executed, the attacker will have complete control of the system.
By exploiting the vulnerability, malicious actors can execute arbitrary code on ManageEngine without authentication if SAML-based single sign-on (SSO) was enabled at least once prior to the attack.
Countless ManageEngine products are vulnerable to this vulnerability. Fortunately, Zoho has released patches as of October 27, 2022, upgrading the version of the third-party module for better security.
On Friday, the Horizon3 attack team issued a stern warning to administrators about the proof-of-concept (PoC) exploit for CVE-2022-47966 they had created.
See also: FBI: Hackers exploit critical Zoho zero-day bug

This vulnerability is fairly easy to exploit and is a prime target for attackers who take a “spray and pray” approach across the Internet. As Horizon3 security researcher James Horseman, this security flaw allows remote code execution as NT AUTHORITY\SYSTEM, giving an attacker unfettered control over the system.
“When a user realizes they have been the victim of an attack, it is important to investigate the extent of the damage the attacker has caused. Once an attacker gains SYSTEM-level access to the endpoint, it is expected that they will attempt to exfiltrate credentials by exploiting LSASS or exploiting publicly available tools to access stored application credentials as a means of lateral movement.“
Although they have not yet released technical details and have only shared indicators of compromise (IOCs) to help defenders identify if their systems have been affected, Horizon3 plans to release the Proof-of-Concept exploit later this week.
Horizon3 researchers presented a screenshot depicting their exploit being run against an unprotected ManageEngine ServiceDesk Plus, providing proof of its capabilities.
See also: Hackers exploit a new Zoho ServiceDesk exploit
By investigating just two of ManageEngine's vulnerable products, ServiceDesk Plus and Endpoint Central, Horseman discovered thousands of unpatched servers that were publicly exposed online via Shodan.
Of the exposed ManageEngine products, a striking number had SAML enabled, leaving approximately 10% of them vulnerable to CVE-2022-47966 attacks.
