Back to search
CVE-2019-19034
Published: Mar 23, 2020
Modified: Aug 5, 2024
PUBLISHED
Description
Zoho ManageEngine Asset Explorer 6.5 does not validate the System Center Configuration Manager (SCCM) database username when dynamically generating a command to schedule scans for SCCM. This allows an attacker to execute arbitrary commands on the AssetExplorer Server with NT AUTHORITY/SYSTEM privileges.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://www.manageengine.com/products/asset-explorer/sp-readme.html
x_refsource_CONFIRM
20200515 Asset Explorer (Windows & Linux) - Authenticated Command Execution
mailing-list
x_refsource_FULLDISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now