Impact
Zohocorp ManageEngine Endpoint Central versions below 11.5.2600.15 are vulnerable to privilege escalation due to an outdated component. The flaw allows an attacker who can manipulate the outdated component to gain higher privileges within the system. This weakness corresponds to CWE‑269, Incorrect Privilege Assignment, and could compromise confidentiality, integrity, or availability of the affected environment if elevated privileges are used for malicious actions.
Affected Systems
Affected systems are Zohocorp ManageEngine Endpoint Central installations running any version prior to 11.5.2600.15. The exact affected components are not enumerated beyond the overall product, but the vulnerability is triggered by the presence of an outdated dependency that is still in use. All customers who have not upgraded past the 11.5.2600.15 release are potentially exposed.
Risk and Exploitability
The CVSS base score of 6.3 indicates moderate severity, and the absence of an EPSS score means there is currently no publicly recorded exploitation data. The vulnerability is not listed in the CISA KEV catalog, so no confirmed active exploits are known as of the latest advisory. Attackers would likely need local or authenticated access to the Endpoint Central server to influence the outdated component, then leverage the privilege escalation to increase their rights. Once elevated, an attacker could pivot within the network or compromise additional systems. Due to the lack of remote exploitability data, the risk mainly applies to environments where the product is exposed to potentially untrusted users.
OpenCVE Enrichment