Support
 
Phone Live Chat
 
Support
 
US: +1 888 720 9500
US: +1 800 443 6694
Intl: +1 925 924 9500
Aus: +1 800 631 268
UK: 0800 028 6590
CN: +86 400 660 8680

Direct Inward Dialing: +1 408 916 9393

 
 
 
 
 
Security Updates

Authenticated RCE vulnerability - ManageEngine ADManager Plus

Vulnerability details
Severity Low
CVE ID CVE- 2023-38743
Affected software version Build 7188 and older
Fixed version Build 7200
Fixed on June 13, 2023

Details

In ADManager Plus builds 7188 and older, an authenticated RCE vulnerability was reported in High Availability module. This has been fixed in the build 7200 and the release notes for it can be found here.

Impact

Authenticated users with admin privileges can run an arbitrary command on the host machine in which ADManager Plus is installed.

Steps to update

Update ADManager Plus instance to its latest build by installing the service pack.

Acknowledgement

This issue was reported by Nguyen Quoc Viet (Petrus Viet) of VNG Security Researcher.

 

Select a language to translate the contents of this web page:

Need further assistance?

Fill this form, and we'll contact you rightaway.

Request Support

  •  
  • *
     
  • *
     
  • *
     
  • By submitting you agree to processing of personal data according to the Privacy Policy.

"Thank you for submitting your request.

Our technical support team will get in touch with you at the earliest."

ADManager Plus Trusted By

The one-stop solution to Active Directory Management and Reporting
Email Download Link email-download-top