Impact
Zohocorp ManageEngine Endpoint Central versions prior to 11.5.2605.01 can be locally exploited to gain elevated privileges. The flaw arises when the application loads a DLL from an untrusted path, allowing an attacker with user‑level access to replace the DLL with a malicious one and execute code with higher privileges. This results in compromised integrity and confidentiality on the affected machine.
Affected Systems
The vulnerability affects ManageEngine Endpoint Central deployments from Zohocorp. Any installation using a version older than 11.5.2605.01 is susceptible. Users should verify their deployment version and plan to upgrade when possible.
Risk and Exploitability
The CVSS score of 5.0 indicates moderate severity. Because the fault requires local access and the EPSS score is not available, the likelihood of exploitation is moderate to low, and the exposure is limited to the local machine. The vulnerability is not listed in the CISA KEV catalog, reducing the search for known exploits; however, the flaw is straightforward to abuse once local access is achieved.
OpenCVE Enrichment