CISA Warns Of Bug In Zoho ADSelfService Plus

Share post:

The United States Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are exploiting a critical vulnerability known as CVE-2021-40539 in Zoho’s ManageEngine ADSelfService Plus password management solution that gives them the privilege to take over a system.

The vulnerability is considered critical because it could allow a remote, unauthenticated attacker to execute arbitrary code on a vulnerable system. Security notifications from the company and a warning from CISA suggested that the bug was exploited in the wild.

Currently, information about CVE-2021-40539, the fifth critical vulnerability reported for Zoho ManageEngine ADSelfService Plus in 2021, is sparse, with a severity score yet to be calculated by the National Institute of Standards and Technology.

However, companies with ADSelfService Plus builds lower than 6114 are recommended to install the latest developer update available from the service pack.

For more information, read the original story in Bleeping Computer

 

Featured Tech Jobs

SUBSCRIBE NOW

Related articles

Lawsuit requires Pegasus spyware to provide code used to spy on WhatsApp users

NSO Group, the developer behind the sophisticated Pegasus spyware, has been ordered by a US court to provide...

OpenAI claims New York Times manipulated ChatGPT “fabricate data”

OpenAI has challenged the New York Times' copyright lawsuit, asserting the newspaper manipulated ChatGPT to fabricate evidence. The...

Wendy’s leverages digital tech to test “surge pricing”

Wendy's is set to experiment with Uber-like surge pricing, a concept referred to as "dynamic pricing," starting in...

Meta is gathering data on Quest virtual reality users

Meta's latest policy update reveals plans to start collecting "anonymized" data from its Quest headset users, intensifying concerns...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways