CVE-2020-9367

CWE-4273 documents3 sources
Severity
7.8HIGH
EPSS
0.2%
top 60.06%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 18
Latest updateMay 24

Description

The MPS Agent in Zoho ManageEngine Desktop Central MSP build MSP build 10.0.486 is vulnerable to DLL Hijacking: dcinventory.exe and dcconfig.exe try to load CSUNSAPI.dll without supplying the complete path. The issue is aggravated because this DLL is missing from the installation, thus making it possible to hijack the DLL and subsequently inject code, leading to an escalation of privilege to NT AUTHORITY\SYSTEM.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-25m6-rgph-v3gw: The MPS Agent in Zoho ManageEngine Desktop Central MSP build MSP build 102022-05-24
CVEList
CVE-2020-9367: The MPS Agent in Zoho ManageEngine Desktop Central MSP build MSP build 102021-03-18
CVE-2020-9367 (HIGH CVSS 7.8) | The MPS Agent in Zoho ManageEngine | cvebase.io