Vulnerability record · CVE-2018-5353 · published 30 September 2020
CVE-2018-5353: Zohocorp manageengine adselfservice plus authentication bypass by spoofing vulnerability
Zohocorp · Manageengine Adselfservice Plus
The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execute code and escalate privileges via spoofing. It does not authenticate the intended server before opening a browser window. An unauthenticated attacker capable of conducting a spoofing attack can redirect the browser to gain execution in the context of the WinLogon.exe process. If Network Level Authentication is not enforced, the vulnerability can be exploited via RDP. Additionally, if the web server has a misconfigured certificate then no spoofing attack is required
Description
The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execute code and escalate privileges via spoofing. It does not authenticate the intended server before opening a browser window. An unauthenticated attacker capable of conducting a spoofing attack can redirect the browser to gain execution in the context of the WinLogon.exe process. If Network Level Authentication is not enforced, the vulnerability can be exploited via RDP. Additionally, if the web server has a misconfigured certificate then no spoofing attack is required
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/missing0x00/CVE-2018-5353 | ExploitThird Party Advisory |
| https://www.manageengine.com/products/self-service-password/release-notes.html | Release NotesVendor Advisory |
| https://github.com/missing0x00/CVE-2018-5353 | ExploitThird Party Advisory |
| https://www.manageengine.com/products/self-service-password/release-notes.html | Release NotesVendor Advisory |
Track CVE-2018-5353 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-5353), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.