Impact
The flaw resides in Zohocorp ManageEngine Endpoint Central agents released before version 11.5.2605.01. During an agent upgrade the software incorrectly handles privilege assignment, allowing a local user to elevate their privileges on the host system. This is a classic local privilege escalation flaw (CWE‑269).
Affected Systems
Systems running Zohocorp ManageEngine Endpoint Central, version 11.5.2605.00 or earlier, are affected. The issue is specific to the agent component that performs automatic upgrades.
Risk and Exploitability
The vulnerability carries a CVSS score of 5.7, indicating moderate severity, and its EPSS score is not available. It is not listed in the CISA KEV catalog. The attack vector is local; an attacker must be able to execute code on the machine that hosts the agent. No remote exploitation evidence is provided, but a user with local access could trigger the upgrade process to gain elevated privileges.
OpenCVE Enrichment