Impact
This vulnerability involves the unvalidated extraction of JAR files in ManageEngine Endpoint Central, allowing a user to elevate privileges. The flaw corresponds to CWE‑269, representing unauthorized access to privileged resources, and can enable a user with limited permissions to perform operations that should be restricted.
Affected Systems
Zohocorp ManageEngine Endpoint Central is affected. Versions before 11.4.2540.23 are vulnerable; any instance running a lower release must be considered at risk.
Risk and Exploitability
The CVSS score of 6.3 indicates moderate severity, and the EPSS score is not released, suggesting no publicly available exploitation data. The vulnerability is not listed in the CISA KEV catalog. The likely attack path infers that local access to the JAR extraction mechanism is required; an attacker with user‑level privileges could take advantage of the flaw to write files to privileged locations during extraction, thereby escalating privileges.
OpenCVE Enrichment