zohocorp manageengine-desktop-central CVE-2020-15588 is a vulnerability in Zoho Corp Manageengine Desktop Central
Published on July 29, 2020

An issue was discovered in the client side of Zoho ManageEngine Desktop Central 10.0.552.W. An attacker-controlled server can trigger an integer overflow in InternetSendRequestEx and InternetSendRequestByBitrate that leads to a heap-based buffer overflow and Remote Code Execution with SYSTEM privileges. This issue will occur only when untrusted communication is initiated with server. In cloud, Agent will always connect with trusted communication.

NVD


Products Associated with CVE-2020-15588

Want to know whenever a new CVE is published for Zoho Corp Manageengine Desktop Central? stack.watch will email you.

 

Exploit Probability

EPSS
5.98%
Percentile
90.50%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.