The event analysis component in Zoho ManageEngine ADAudit Plus 7.1.1 allows an attacker to bypass audit detection by creating or renaming user accounts with a "$" symbol suffix. NOTE: the vendor states "We do not consider this as a security bug and it's an expected behaviour."
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 15 Oct 2024 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-10-15T20:44:37.826Z

Reserved: 2023-05-15T00:00:00

Link: CVE-2023-32783

cve-icon Vulnrichment

Updated: 2024-08-02T15:25:37.051Z

cve-icon NVD

Status : Modified

Published: 2023-08-07T17:15:11.080

Modified: 2024-11-21T08:04:01.120

Link: CVE-2023-32783

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.