Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2022-29457

Severity
8.8HIGH
EPSS
8.3%
top 7.77%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedApr 18
Latest updateMay 11

Description

Zoho ManageEngine ADSelfService Plus before 6121, ADAuditPlus 7060, Exchange Reporter Plus 5701, and ADManagerPlus 7131 allow NTLM Hash disclosure during certain storage-path configuration steps.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Patches

🔴Vulnerability Details

2
GHSA
GHSA-gjvq-53x4-jvx9: Zoho ManageEngine ADSelfService Plus before 6121, ADAuditPlus 7060, Exchange Reporter Plus 5701, and ADManagerPlus 7131 allow NTLM Hash disclosure dur2022-04-19
CVEList
CVE-2022-29457: Zoho ManageEngine ADSelfService Plus before 6121, ADAuditPlus 7060, Exchange Reporter Plus 5701, and ADManagerPlus 7131 allow NTLM Hash disclosure dur2022-04-18

💥Exploits & PoCs

1
Exploit-DB
ManageEngine ADSelfService Plus Build 6118 - NTLMv2 Hash Exposure2022-05-11
CVE-2022-29457 (HIGH CVSS 8.8) | Zoho ManageEngine ADSelfService Plu | cvebase.io