peter bassill · operator
$ cve CVE-2020-10189 JSON

CVE-2020-10189 KEV EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 99.9% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2022-05-03.

Description

Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImage in the FileStorage class. This is related to the CewolfServlet and MDMLogUploaderServlet servlets.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS99.94% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-502
On CISA KEVyes — remediate by 2022-05-03
Public exploityes
Published2020-03-06
Last modified2026-06-17

CISA KEV

NameZoho ManageEngine Desktop Central File Upload Vulnerability
Added2021-11-03
Due2022-05-03
Vendor / productZoho / ManageEngine
Ransomware usenone reported

Affected (1)

VendorProduct
zohocorpmanageengine desktop central

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD