peter bassill · operator
$ cve CVE-2017-11346 JSON

CVE-2017-11346 EXPLOIT

9.8
CRITICAL · CVSS 3.0 · EPSS 43.3% (pctl 99)

Patch early

A public exploit exists.

Description

Zoho ManageEngine Desktop Central before build 100092 allows remote attackers to execute arbitrary code via vectors involving the upload of help desk videos.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS43.27% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-20
On CISA KEVno
Public exploityes
Published2017-07-17
Last modified2026-06-17

Affected (1)

VendorProduct
zohocorpmanageengine desktop central

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD