CVE-2021-44757
9.1
CRITICAL · CVSS 3.1 · EPSS 24.2% (pctl 98)
Patch early
EPSS 24.2% — above the 10% action threshold.
Description
Zoho ManageEngine Desktop Central before 10.1.2137.9 and Desktop Central MSP before 10.1.2137.9 allow attackers to bypass authentication, and read sensitive information or upload an arbitrary ZIP archive to the server.
Scoring
| CVSS | 9.1 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
| EPSS | 24.2% — more likely to be exploited than 98% of all CVEs |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2022-01-18 |
| Last modified | 2026-06-17 |
Affected (2)
| Vendor | Product |
|---|---|
| zohocorp | manageengine desktop central |
| zohocorp | manageengine desktop central managed service providers |
References
- https://pitstop.manageengine.com/portal/en/community/topic/a-critical-security-patch-released-in-desktop-central-and-desktop-central-msp-for-cve-2021-44757-17-1-2022
- https://pitstop.manageengine.com/portal/en/community/topic/a-critical-security-patch-released-in-desktop-central-and-desktop-central-msp-for-cve-2021-44757-17-1-2022
→ the Explorer · watch your stack · NVD