Vulnerability record · CVE-2021-37539 · published 27 September 2021
CVE-2021-37539: Zoho ManageEngine ADManager Plus unrestricted file upload enables RCE
Zohocorp · Manageengine Admanager Plus
Zoho ManageEngine ADManager Plus before build 7111 allows unrestricted file upload, which the vendor classifies as leading to remote code execution. The flaw is network-reachable with no authentication or user interaction required, so any exposed instance is directly at risk. It matters because ADManager Plus is an Active Directory management tool, making successful exploitation a path into privileged directory infrastructure.
Description
Zoho ManageEngine ADManager Plus before 7111 is vulnerable to unrestricted file which leads to Remote code execution.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or interaction required, and an EPSS score near the top percentile, makes this an urgent patch for any internet- or broadly reachable deployment.
What it is
Zoho ManageEngine ADManager Plus before build 7111 allows unrestricted file upload, which the vendor classifies as leading to remote code execution. The flaw is network-reachable with no authentication or user interaction required, so any exposed instance is directly at risk. It matters because ADManager Plus is an Active Directory management tool, making successful exploitation a path into privileged directory infrastructure.
Impact
An unauthenticated attacker can upload a file of their choosing and achieve remote code execution on the ADManager Plus server. That yields code execution in the context of the application, which typically has broad access to Active Directory.
Attack surface
Reached over the network via the application's HTTP interface, per the CVSS vector AV:N/AC:L/PR:N/UI:N. No authentication and no user interaction are required.
Exploitation
CISA KEV does not list this CVE, but EPSS is very high at 0.92868 (99.8th percentile), indicating strong predicted exploitation activity. The references are only product and vendor advisory pages, so no public exploit or in-the-wild confirmation is documented in this record.
What to do
- Upgrade ADManager Plus to build 7111 or later, per the vendor release notes.
- Do not expose the ADManager Plus web interface to the internet; restrict it to trusted management networks or VPN.
- Restrict and monitor upload directories, and block execution of uploaded files at the web server or application layer.
- Run the service under a least-privilege account so post-exploitation access to Active Directory is limited.
- Audit for unauthorized administrative accounts or changes in ADManager Plus and connected directory services.
Detection
- Monitor the ADManager Plus upload endpoints for file writes with executable extensions or unexpected content types.
- Alert on new process creation spawned by the ADManager Plus service or its web server worker processes.
- Review web server and application logs for anomalous POST requests to upload paths from untrusted source addresses.
- Watch for unexpected outbound connections or new scheduled tasks originating from the ADManager Plus host.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.manageengine.com | Product |
| https://www.manageengine.com/products/ad-manager/release-notes.html#7111 | Vendor Advisory |
| https://www.manageengine.com | Product |
| https://www.manageengine.com/products/ad-manager/release-notes.html#7111 | Vendor Advisory |
Track CVE-2021-37539 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-37539), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.