CVE-2020-10189 KEV EXPLOIT
9.8
CRITICAL · CVSS 3.1 · EPSS 99.9% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2022-05-03.
Description
Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImage in the FileStorage class. This is related to the CewolfServlet and MDMLogUploaderServlet servlets.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 99.94% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-502 |
| On CISA KEV | yes — remediate by 2022-05-03 |
| Public exploit | yes |
| Published | 2020-03-06 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Zoho ManageEngine Desktop Central File Upload Vulnerability |
|---|---|
| Added | 2021-11-03 |
| Due | 2022-05-03 |
| Vendor / product | Zoho / ManageEngine |
| Ransomware use | none reported |
Affected (1)
| Vendor | Product |
|---|---|
| zohocorp | manageengine desktop central |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | ManageEngine Desktop Central - Java Deserialization (Metasploit) | 2020-03-17 |
References
- http://packetstormsecurity.com/files/156730/ManageEngine-Desktop-Central-Java-Deserialization.html
- https://cwe.mitre.org/data/definitions/502.html
- https://srcincite.io/advisories/src-2020-0011/
- https://srcincite.io/pocs/src-2020-0011.py.txt
- https://www.manageengine.com/products/desktop-central/remote-code-execution-vulnerability.html
- https://www.zdnet.com/article/zoho-zero-day-published-on-twitter/
- http://packetstormsecurity.com/files/156730/ManageEngine-Desktop-Central-Java-Deserialization.html
- https://cwe.mitre.org/data/definitions/502.html
- https://srcincite.io/advisories/src-2020-0011/
- https://srcincite.io/pocs/src-2020-0011.py.txt
- https://www.manageengine.com/products/desktop-central/remote-code-execution-vulnerability.html
- https://www.zdnet.com/article/zoho-zero-day-published-on-twitter/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-10189
→ the Explorer · watch your stack · NVD