Impact
The vulnerability is a credential compromise in ZohoCorp’s ManageEngine Applications Manager installer, which contains a Google Cloud service‑account private key. An unauthenticated attacker who obtains the installer can extract the key and use it to impersonate the service account, thereby gaining full read/write/management privileges over the associated Cloud resources. This flaw maps to CWE‑321, a known issue of improper key management leading to data exposure and unauthorized access.
Affected Systems
The issue affects Zohocorp’s ManageEngine Applications Manager versions 182200 and earlier. Administrators should review whether any systems are running these specific versions or older releases and consider updating to the latest certified build.
Risk and Exploitability
The CVSS score of 10 classifies this as a critical vulnerability, although the EPSS score is not available, indicating that exploitation probability data is missing. The KEV catalog does not list this flaw, so there are no publicly confirmed exotic exploit packages, but the high severity and lack of a key restriction make it an attractive target. The likely attack vector is unauthenticated download or analysis of the installer, after which the attacker can extract the private key and impersonate the service account.
OpenCVE Enrichment