漏洞描述
Zoho ManageEngine Desktop Central before 10.0.474 is vulnerable to a deserialization of untrusted data, which permits remote code execution.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2020-10189↗www.manageengine.comhttps://www.manageengine.com/products/desktop-central/remote-code-execution-vulnerability.html↗y4er.comhttps://y4er.com/posts/cve-2020-10189-zoho-manageengine-rce/↗cwe.mitre.orghttps://cwe.mitre.org/data/definitions/502.html↗