This vulnerability is exploitable only by technicians who have the “Impersonate as Admin” option enabled.
Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 15 Dec 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 15 Dec 2025 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Zohocorp ManageEngine ADManager Plus versions before 8025 are vulnerable to NTLM Hash Exposure. This vulnerability is exploitable only by technicians who have the “Impersonate as Admin” option enabled. | |
| Title | NTLM Hash Exposure Vulnerability | |
| First Time appeared |
Zohocorp
Zohocorp manageengine Admanager Plus |
|
| Weaknesses | CWE-200 | |
| CPEs | cpe:2.3:a:zohocorp:manageengine_admanager_plus:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Zohocorp
Zohocorp manageengine Admanager Plus |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Zohocorp
Published:
Updated: 2025-12-15T13:11:14.660Z
Reserved: 2025-10-13T04:36:28.773Z
Link: CVE-2025-11670
Updated: 2025-12-15T13:11:09.639Z
Status : Awaiting Analysis
Published: 2025-12-15T11:15:38.607
Modified: 2025-12-15T18:22:13.783
Link: CVE-2025-11670
No data.
OpenCVE Enrichment
No data.