Coming Soon...

Q-CERT website is currently under maintenance. We should be back shortly. Thank you for yor patience.

Unauthenticated Remote Code Execution Vulnerability in ManageEngine ADAudit Plus

Issued: 
Sunday, 3 July, 2022
Last Revision: 
Thursday, 7 July, 2022
Vendor: 
Severity Level: 
Summary: 
A remote code execution (RCE) vulnerability is discovered in Manage Engine ADAudit Plus. ADAudit Plus is a Windows auditing, security and compliance solution from Zoho used by large enterprises to monitor changes, real time risk alerting and compliance reporting for the Active Directory (AD) environment.
 
Due to a serious flaw identified as CVE-2022-28219, attackers are able to access domain administrator accounts and steal confidential information. Underlying Java deserialization, blind XXE injection, and path traversal flaws are what lead to this vulnerability.
 
On GitHub, the proof-of-concept exploit is available. For ransomware operators and initial access brokers, the bug's characteristics and potential consequences make it a topic of great interest.
 
Vulnerability Details:
 
CVE/VulnerabilityDescriptionCVSS 3.0 Score
CVE-2022-28219CVE-2022-28219 Remote Code Execution vulnerability 9.89.8

 

Affected Products:

CVE/VulnerabilityAffected Product(s)
CVE-2022-28219All ADAudit Plus builds below 7060

 

Recommendation: 

Organizations using ADAudit Plus are requested to upgrade their instances to the 7060 or latest build in order to prevent attacks against the infrastructure.