← Vulnerability feed

Vulnerability record · CVE-2021-42847 · published 11 November 2021

CVE-2021-42847: ManageEngine ADAudit Plus arbitrary file write and execution

Zohocorp · Manageengine Adaudit Plus

Zoho ManageEngine ADAudit Plus before build 7006 permits attackers to write arbitrary files and then execute them. The flaw is remotely reachable with no authentication or user interaction, and the CVSS 3.1 base score is 9.8 (critical). Because the product is an Active Directory auditing tool, compromise can expose or tamper with directory monitoring data and the host itself.

9.8 CVSS 3.1 Critical EPSS 70% · top 0.6%
9.8CVSS 3.1 base score, v2 7.5
70%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Zoho ManageEngine ADAudit Plus before 7006 allows attackers to write to, and execute, arbitrary files.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

critical priorityUnauthenticated network-reachable arbitrary file write leading to code execution with a 9.8 CVSS score and high EPSS probability.

What it is

Zoho ManageEngine ADAudit Plus before build 7006 permits attackers to write arbitrary files and then execute them. The flaw is remotely reachable with no authentication or user interaction, and the CVSS 3.1 base score is 9.8 (critical). Because the product is an Active Directory auditing tool, compromise can expose or tamper with directory monitoring data and the host itself.

Impact

An unauthenticated attacker can write and execute arbitrary files on the ADAudit Plus server, gaining code execution in the context of the service. That typically yields full control of the host and any credentials or AD data it processes.

Attack surface

Reached over the network via the ADAudit Plus web interface, per the CVSS vector AV:N/AC:L/PR:N/UI:N. No authentication and no user interaction are required.

Exploitation

Not listed in CISA KEV and no ransomware associations are recorded. EPSS is high (0.70325, 99.35th percentile), and a public Packet Storm remote code execution write-up exists, indicating exploit code is publicly available.

What to do

  • Upgrade ADAudit Plus to build 7006 or later per the vendor advisory.
  • Restrict network access to the ADAudit Plus web interface to trusted management networks only.
  • Run the service under a least-privilege account and remove write/execute permissions from web-accessible directories.
  • Monitor the vendor advisory and apply any follow-up patches promptly.

Detection

  • Alert on new or modified executable files in ADAudit Plus web and application directories.
  • Monitor for unexpected child processes spawned by the ADAudit Plus service account.
  • Review web server logs for suspicious upload or file-write requests to ADAudit Plus endpoints.
  • Correlate outbound connections from the ADAudit Plus host with file creation events.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-42847 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-47966Zoho ManageEngine on-premise products RCE via SAML SSO and xmlsecMultiple Zoho ManageEngine on-premise products use Apache Santuario xmlsec 1.4.1, whose XSLT features by design leave certain security protections to…KEVEPSS 100%analysed9.8CVE-2023-48792Zohocorp manageengine adaudit plus sql injection vulnerabilityZoho ManageEngine ADAudit Plus through 7250 is vulnerable to SQL Injection in the report export option.EPSS 7.0%9.8CVE-2023-48793Zohocorp manageengine adaudit plus sql injection vulnerabilityZoho ManageEngine ADAudit Plus through 7250 allows SQL Injection in the aggregate report feature.EPSS 7.0%9.8CVE-2022-28219Zoho ManageEngine ADAudit Plus unauthenticated XXE leading to RCECewolf in Zoho ManageEngine ADAudit Plus before 7060 is vulnerable to an unauthenticated XML external entity (XXE) attack that leads to remote code e…EPSS 97%analysed9.8CVE-2020-24786Zohocorp manageengine adselfservice plus improper authentication vulnerabilityAn issue was discovered in Zoho ManageEngine Exchange Reporter Plus before build number 5510, AD360 before build number 4228, ADSelfService Plus befo…EPSS 13%9.8CVE-2020-11532ManageEngine DataSecurity Plus default admin credentials allow auth bypassZoho ManageEngine DataSecurity Plus before 6.0.1 ships with default admin credentials used to communicate with a DataEngine Xnode server. An attacker…EPSS 77%analysed9.8CVE-2018-10466Zohocorp manageengine adaudit plus sql injection vulnerabilityZoho ManageEngine ADAudit Plus before 5.0.0 build 5100 allows blind SQL Injection.EPSS 17%8.8CVE-2024-49574Zohocorp manageengine adaudit plus sql injection vulnerabilityZohocorp ManageEngine ADAudit Plus versions below 8123 are vulnerable to SQL Injection in the reports module.EPSS 3.6%

Source: NIST National Vulnerability Database (record CVE-2021-42847), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.