CRITICAL

CVE-2018-5353

CVSS v3

9.8

CRITICAL

EPSS Score

15.3%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execute code and escalate privileges via spoofing. It does not authenticate the intended server before opening a browser window. An unauthenticated attacker capable of conducting a spoofing attack can redirect the browser to gain execution in the context of the WinLogon.exe process. If Network Level Authentication is not enforced, the vulnerability can be exploited via RDP. Additionally, if the web server has a misconfigured certificate then no spoofing attack is required

Technical details

Published
9/30/2020

Frequently asked questions

What is CVE-2018-5353?

The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execute code and escalate privileges via spoofing. It does not authenticate the intended server before opening a browser window. An unauthenticated attacker capable of conducting a spoofing attack can redirect the browser to gain execution in the context of the WinLogon.exe process. If Network Level Authentication is not enforced, the vulnerability can be exploited via RDP. Additionally, if the web server has a misconfigured certificate then no spoofing attack is required

Is CVE-2018-5353 actively exploited?

Active exploitation of CVE-2018-5353 has not been confirmed. The EPSS score is 15.3%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2018-5353?

CVE-2018-5353 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2018-5353 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.