CVE-2018-5353

CWE-290CWE-4065 documents5 sources
Severity
9.8CRITICAL
EPSS
15.3%
top 5.37%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 30
Latest updateMay 24

Description

The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execute code and escalate privileges via spoofing. It does not authenticate the intended server before opening a browser window. An unauthenticated attacker capable of conducting a spoofing attack can redirect the browser to gain execution in the context of the WinLogon.exe process. If Network Level Authentication is not enforced, the vulnerability can be exploited via RDP. Additionโ€ฆ

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages1 packages

๐Ÿ”ดVulnerability Details

2
GHSA
GHSA-p8cf-jjc3-phj5: The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5โ†—2022-05-24
โ–ถ
CVEList
CVE-2018-5353: The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5โ†—2020-09-29
โ–ถ

๐Ÿ“‹Vendor Advisories

1
Red Hat
avahi: DNS amplification and reflection to spoofed addressesโ†—2018-11-08
โ–ถ
CVE-2018-5353 (CRITICAL CVSS 9.8) | The custom GINA/CP module in Zoho M | cvebase.io