CISA and FBI Release Alert on Active Exploitation of CVE-2021-44077 in Zoho ManageEngine ServiceDesk Plus

CVE-2021-44077 is an unauthenticated remote code execution vulnerability that affects all ServiceDesk Plus versions up to, and including, version 11305. More https://us-cert.cisa.gov/ncas/alerts/aa21-336a

Continue ReadingCISA and FBI Release Alert on Active Exploitation of CVE-2021-44077 in Zoho ManageEngine ServiceDesk Plus

BeyondTrust – Exploiting the vulnerability will give a local unprivileged attacker SYSTEM level privileges.

BeyondTrust Privilege Management for Windows contains a local privilege escalation vulnerability prior to version 21.6. More https://github.com/mandiant/Vulnerability-Disclosures/blob/master/MNDT-2021-0008/MNDT-2021-0008.md  

Continue ReadingBeyondTrust – Exploiting the vulnerability will give a local unprivileged attacker SYSTEM level privileges.