Vulnerability record · CVE-2014-7862 · published 4 January 2018
CVE-2014-7862: ManageEngine Desktop Central DCPluginServelet missing access control allows admin creation
Zohocorp · Desktop Central
The DCPluginServelet servlet in ManageEngine Desktop Central and Desktop Central MSP before build 90109 fails to enforce access controls, letting a remote unauthenticated attacker create administrator accounts through the addPlugInUser action. Because the flaw yields full administrative access to the endpoint management platform, it is a severe risk to any exposed instance.
Description
The DCPluginServelet servlet in ManageEngine Desktop Central and Desktop Central MSP before build 90109 allows remote attackers to create administrator accounts via an addPlugInUser action.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote creation of administrator accounts on a management platform with a CVSS of 9.8 and very high EPSS makes this an urgent exposure.
What it is
The DCPluginServelet servlet in ManageEngine Desktop Central and Desktop Central MSP before build 90109 fails to enforce access controls, letting a remote unauthenticated attacker create administrator accounts through the addPlugInUser action. Because the flaw yields full administrative access to the endpoint management platform, it is a severe risk to any exposed instance.
Impact
An attacker gains a new administrator account on the Desktop Central server, which can be used to control managed endpoints, deploy software or scripts, and access data handled by the platform.
Attack surface
Reachable over the network via HTTP requests to the DCPluginServelet servlet; the CVSS vector shows no privileges or user interaction required, so no authentication is needed.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.81, 99.6th percentile) and public references include a Rapid7 Metasploit module and proof-of-concept advisories, indicating mature, widely available exploit code.
What to do
- Upgrade Desktop Central and Desktop Central MSP to build 90109 or later.
- Restrict network access to the Desktop Central web interface and servlet paths to trusted management networks only.
- Audit existing administrator accounts and remove any unrecognized or unauthorized accounts.
- Monitor and alert on addPlugInUser requests and unexpected account creation events.
Detection
- Search web server and application logs for requests to DCPluginServelet with the addPlugInUser action.
- Alert on creation of new administrator accounts, especially from unexpected source IPs or outside change windows.
- Review Desktop Central audit logs for anomalous administrative account changes.
- Monitor for Metasploit module traffic or known exploit signatures targeting the servlet.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2014-7862 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2014-7862), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.