11 lines
No EOL
649 B
Text
11 lines
No EOL
649 B
Text
# Exploit Title: Zoho ManageEngine ADManager Plus 6.6 (Build < 6659) Privilege Escalation
|
|
# Date: 15th April 2019
|
|
# Exploit Author: Digital Interruption
|
|
# Vendor Homepage: https://www.manageengine.co.uk/
|
|
# Version: 6.6 (Build 6658)
|
|
# Tested on: Windows Server 2012 R2
|
|
# CVE : CVE-2018-19374
|
|
|
|
Due to weak permissions setup on the bin, lib and tools directories within the ManageEngine installation directory, it is possible for any authenticated user to modify several core files.
|
|
|
|
To escalate privileges to that of LOCAL SYSTEM, drop a payload onto the system and then add a line to bin\ChangeJRE.bat to execute it every time the system is rebooted. |