CVE-2021-44515 — Zoho Desktop Central Authentication Bypass Vulnerability
CVE-2021-44515: Zoho Desktop Central Authentication Bypass Vulnerability
CISA Known Exploited Vulnerability (KEV)
| Vendor / project | Zoho |
| Product | Desktop Central |
| Date added | 2021-12-10 |
| Due date | 2021-12-24 |
| Ransomware campaign use | Unknown |
Description
Zoho Desktop Central contains an authentication bypass vulnerability that could allow an attacker to execute arbitrary code in the Desktop Central MSP server.
Required action (CISA)
Apply updates per vendor instructions.
Notes
https://nvd.nist.gov/vuln/detail/CVE-2021-44515
References
- NVD: https://nvd.nist.gov/vuln/detail/CVE-2021-44515
- KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog