CVE-2018-5353

The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execute code and escalate privileges via spoofing. It does not authenticate the intended server before opening a browser window. An unauthenticated attacker capable of conducting a spoofing attack can redirect the browser to gain execution in the context of the WinLogon.exe process. If Network Level Authentication is not enforced, the vulnerability can be exploited via RDP. Additionally, if the web server has a misconfigured certificate then no spoofing attack is required
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 94%
VendorProductVersion
zohocorpmanageengine_adselfservice_plus
𝑥
< 5.5
zohocorpmanageengine_adselfservice_plus
5.5
zohocorpmanageengine_adselfservice_plus
5.5:5500
zohocorpmanageengine_adselfservice_plus
5.5:5501
zohocorpmanageengine_adselfservice_plus
5.5:5502
zohocorpmanageengine_adselfservice_plus
5.5:5503
zohocorpmanageengine_adselfservice_plus
5.5:5504
zohocorpmanageengine_adselfservice_plus
5.5:5505
zohocorpmanageengine_adselfservice_plus
5.5:5506
zohocorpmanageengine_adselfservice_plus
5.5:5507
zohocorpmanageengine_adselfservice_plus
5.5:5508
zohocorpmanageengine_adselfservice_plus
5.5:5509
zohocorpmanageengine_adselfservice_plus
5.5:5510
zohocorpmanageengine_adselfservice_plus
5.5:5511
zohocorpmanageengine_adselfservice_plus
5.5:5512
zohocorpmanageengine_adselfservice_plus
5.5:5513
zohocorpmanageengine_adselfservice_plus
5.5:5514
zohocorpmanageengine_adselfservice_plus
5.5:5515
zohocorpmanageengine_adselfservice_plus
5.5:5516
𝑥
= Vulnerable software versions