⚠ Actively exploited
Added to CISA KEV on 2021-12-01. Federal agencies required to patch by 2021-12-15. Required action: Apply updates per vendor instructions..
Severity
9.8CRITICAL
EPSS
94.3%
top 0.07%
CISA KEV
KEV
Added 2021-12-01
Due 2021-12-15
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedNov 29
KEV addedDec 1
KEV dueDec 15
Latest updateFeb 24
CISA Required Action: Apply updates per vendor instructions.

Description

Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution. This is related to /RestAPI URLs in a servlet, and ImportTechnicians in the Struts configuration.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Patches

🔴Vulnerability Details

3
GHSA
GHSA-xm89-vxjx-jvcg: Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthentica2021-11-30
CVEList
CVE-2021-44077: Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthentica2021-11-29
VulnCheck
Zoho ManageEngine ServiceDesk Plus Remote Code Execution Vulnerability2021

💥Exploits & PoCs

2
Metasploit
ManageEngine ServiceDesk Plus CVE-2021-44077
Nuclei
Zoho ManageEngine ServiceDesk Plus - Remote Code Execution

🔍Detection Rules

1
Suricata
ET EXPLOIT [CISA AA21-336A] Zoho ManageEngine ServiceDesk Possible Exploitation Activity (CVE-2021-44077)2021-12-03

📋Vendor Advisories

1
CISA
Zoho ManageEngine ServiceDesk Plus Remote Code Execution Vulnerability2021-12-01

🕵️Threat Intelligence

2
Unit42
SockDetour – a Silent, Fileless, Socketless Backdoor – Targets U.S. Defense Contractors2022-02-24
Unit42
SockDetour – a Silent, Fileless, Socketless Backdoor – Targets U.S. Defense Contractors2022-02-24
CVE-2021-44077 (CRITICAL CVSS 9.8) | Zoho ManageEngine ServiceDesk Plus | cvebase.io