CVE-2025-10020

8.5

Zohocorp · ManageEngine ADManager Plus

Zohocorp ManageEngine ADManager Plus versions prior to 8024 contain a command injection vulnerability within the Custom Script component that allows for arbitrary command execution by authenticated users.

Executive summary

A critical command injection vulnerability in Zohocorp ManageEngine ADManager Plus allows authenticated attackers to achieve remote code execution on the underlying host system.

Vulnerability

This vulnerability is a command injection flaw (CWE-77) located in the Custom Script component. It requires an authenticated user with sufficient privileges to interact with the component to execute unauthorized system commands.

Business impact

The ability for an authenticated user to perform command injection poses a severe risk to organizational security, as it can lead to full system compromise, lateral movement within the network, and unauthorized access to sensitive Active Directory data. With a CVSS score of 8.5, this high-severity vulnerability represents a significant threat to internal infrastructure and operational integrity.

Remediation

Immediate Action: Upgrade Zohocorp ManageEngine ADManager Plus to build 8024 or later to apply the vendor-supplied security patch.

Proactive Monitoring: Review system and application logs for unexpected process execution, unusual command-line arguments, or unauthorized modifications to system scripts.

Compensating Controls: Implement strict role-based access control (RBAC) to limit the number of users with permissions to access the Custom Script component until the patch is successfully applied.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the high-severity nature of command injection flaws and the potential for total system compromise, organizations should prioritize updating their ManageEngine ADManager Plus environments. Administrators must ensure that the update is applied immediately to eliminate the underlying vulnerability and reduce the risk of unauthorized system-level command execution.

More Zohocorp CVEs all →

History

  1. Disclosed CVE record published
  2. Published in the daily brief critical section
  3. Published in the daily brief high section
  4. Analyst report written
  5. Fix documented version 8024 per CVE record

Sources