CVE-2025-9223
8.8Zohocorp · ManageEngine Applications Manager
Zohocorp ManageEngine Applications Manager is vulnerable to authenticated command injection via the execute program action feature, allowing arbitrary command execution.
Executive summary
An authenticated command injection vulnerability in Zohocorp ManageEngine Applications Manager allows remote attackers to achieve full system compromise.
Vulnerability
The application improperly neutralizes special elements in the execute program action feature, which allows an authenticated user with sufficient privileges to inject and execute arbitrary system commands.
Business impact
The vulnerability carries a CVSS score of 8.8, reflecting its high potential for total system compromise. Successful exploitation could lead to unauthorized data access, complete loss of system integrity, and potential lateral movement within the network, significantly impacting business operations and data security.
Remediation
Immediate Action: Update Zohocorp ManageEngine Applications Manager to version 178200 or later as specified in the vendor security advisory.
Proactive Monitoring: Review audit logs for suspicious execution of system processes or anomalous activity originating from the application service account.
Compensating Controls: Restrict access to the management console to authorized administrative subnets and implement strict egress filtering to prevent the application from initiating unauthorized connections.
Exploitation status
Public Exploit Available: Yes, a public proof-of-concept repository exists on GitHub.
Analyst recommendation
Given the high CVSS score and the existence of a public proof-of-concept, internal security teams should prioritize patching this vulnerability immediately. Ensure that administrative access to the ManageEngine interface is restricted to trusted personnel to mitigate the risk of exploitation by compromised user accounts.