CVE-2020-24397
02.10.2020, 20:15
An issue was discovered in the client side of Zoho ManageEngine Desktop Central 10.0.0.SP-534. An attacker-controlled server can trigger an integer overflow in InternetSendRequestEx and InternetSendRequestByBitrate that leads to a heap-based buffer overflow and Remote Code Execution with SYSTEM privileges.Enginsight
Vendor | Product | Version |
---|---|---|
zohocorp | manageengine_desktop_central | 10.0.0:sp-534 |
𝑥
= Vulnerable software versions