peter bassill · operator
$ cve CVE-2014-7862 JSON

CVE-2014-7862 EXPLOIT

9.8
CRITICAL · CVSS 3.0 · EPSS 81% (pctl 100)

Patch early

A public exploit exists.

Description

The DCPluginServelet servlet in ManageEngine Desktop Central and Desktop Central MSP before build 90109 allows remote attackers to create administrator accounts via an addPlugInUser action.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS81.05% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-264
On CISA KEVno
Public exploityes
Published2018-01-04
Last modified2026-06-17

Affected (1)

VendorProduct
zohocorpdesktop central

Public exploits

SourceTitleDate
exploit-dbManageEngine Desktop Central - Create Administrator2015-01-15

References

→ the Explorer  ·  watch your stack  ·  NVD