Vulnerability record · CVE-2021-42847 · published 11 November 2021
CVE-2021-42847: ManageEngine ADAudit Plus arbitrary file write and execution
Zohocorp · Manageengine Adaudit Plus
Zoho ManageEngine ADAudit Plus before build 7006 permits attackers to write arbitrary files and then execute them. The flaw is remotely reachable with no authentication or user interaction, and the CVSS 3.1 base score is 9.8 (critical). Because the product is an Active Directory auditing tool, compromise can expose or tamper with directory monitoring data and the host itself.
Description
Zoho ManageEngine ADAudit Plus before 7006 allows attackers to write to, and execute, arbitrary files.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable arbitrary file write leading to code execution with a 9.8 CVSS score and high EPSS probability.
What it is
Zoho ManageEngine ADAudit Plus before build 7006 permits attackers to write arbitrary files and then execute them. The flaw is remotely reachable with no authentication or user interaction, and the CVSS 3.1 base score is 9.8 (critical). Because the product is an Active Directory auditing tool, compromise can expose or tamper with directory monitoring data and the host itself.
Impact
An unauthenticated attacker can write and execute arbitrary files on the ADAudit Plus server, gaining code execution in the context of the service. That typically yields full control of the host and any credentials or AD data it processes.
Attack surface
Reached over the network via the ADAudit Plus web interface, per the CVSS vector AV:N/AC:L/PR:N/UI:N. No authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV and no ransomware associations are recorded. EPSS is high (0.70325, 99.35th percentile), and a public Packet Storm remote code execution write-up exists, indicating exploit code is publicly available.
What to do
- Upgrade ADAudit Plus to build 7006 or later per the vendor advisory.
- Restrict network access to the ADAudit Plus web interface to trusted management networks only.
- Run the service under a least-privilege account and remove write/execute permissions from web-accessible directories.
- Monitor the vendor advisory and apply any follow-up patches promptly.
Detection
- Alert on new or modified executable files in ADAudit Plus web and application directories.
- Monitor for unexpected child processes spawned by the ADAudit Plus service account.
- Review web server logs for suspicious upload or file-write requests to ADAudit Plus endpoints.
- Correlate outbound connections from the ADAudit Plus host with file creation events.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2021-42847 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-42847), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.