Vulnerability Description
The MPS Agent in Zoho ManageEngine Desktop Central MSP build MSP build 10.0.486 is vulnerable to DLL Hijacking: dcinventory.exe and dcconfig.exe try to load CSUNSAPI.dll without supplying the complete path. The issue is aggravated because this DLL is missing from the installation, thus making it possible to hijack the DLL and subsequently inject code, leading to an escalation of privilege to NT AUTHORITY\SYSTEM.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zohocorp | Manageengine Desktop Central | 10.0.486 |
Related Weaknesses (CWE)
References
- https://www.manageengine.com/desktop-management-msp/dll-hijacking-vulnerability.Vendor Advisory
- https://www.manageengine.com/desktop-management-msp/dll-hijacking-vulnerability.Vendor Advisory
FAQ
What is CVE-2020-9367?
CVE-2020-9367 is a vulnerability with a CVSS score of 7.8 (HIGH). The MPS Agent in Zoho ManageEngine Desktop Central MSP build MSP build 10.0.486 is vulnerable to DLL Hijacking: dcinventory.exe and dcconfig.exe try to load CSUNSAPI.dll without supplying the complete...
How severe is CVE-2020-9367?
CVE-2020-9367 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-9367?
Check the references section above for vendor advisories and patch information. Affected products include: Zohocorp Manageengine Desktop Central.