Impact
A flaw in the GINA client of Zohocorp ManageEngine ADSelfService Plus allows an attacker to execute arbitrary code on the affected machine. The vulnerability is triggered remotely and can give the adversary full control over the system, potentially compromising confidential data, inserting backdoors, or installing malware. The weakness is an OS command injection (CWE‑78).
Affected Systems
Zohocorp ManageEngine ADSelfService Plus versions prior to build 7001 are susceptible. Only the GINA client component in those builds can be exploited; all other product components are unaffected.
Risk and Exploitability
The CVSS score of 9.8 indicates that the vulnerability is critical and can be fully exploited to compromise system integrity. The EPSS score is not available, so the likelihood of exploitation is not quantified, but corporate environments often expose the GINA client over the network, making the attack vector plausible. The vulnerability is not listed in the CISA KEV catalog, yet its severity and remote nature warrant immediate attention.
OpenCVE Enrichment