Vulnerability record · CVE-2021-44077 · published 29 November 2021
CVE-2021-44077: Zoho ManageEngine ServiceDesk Plus unauthenticated RCE
Zohocorp · Manageengine Servicedesk Plus
Zoho ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP and SupportCenter Plus contain a missing-authentication flaw (CWE-306) in a servlet handling /RestAPI URLs and the ImportTechnicians Struts action. An unauthenticated remote attacker can reach a critical function without credentials and execute code. The flaw is rated CVSS 9.8 and is listed in CISA KEV, so it warrants urgent remediation.
Description
Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution. This is related to /RestAPI URLs in a servlet, and ImportTechnicians in the Struts configuration.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable RCE with CVSS 9.8, KEV listing and very high EPSS probability makes this an urgent patch target.
What it is
Zoho ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP and SupportCenter Plus contain a missing-authentication flaw (CWE-306) in a servlet handling /RestAPI URLs and the ImportTechnicians Struts action. An unauthenticated remote attacker can reach a critical function without credentials and execute code. The flaw is rated CVSS 9.8 and is listed in CISA KEV, so it warrants urgent remediation.
Impact
An attacker gains remote code execution on the affected server, which typically runs with the application's privileges and can lead to full compromise of the host and connected data. No user interaction or prior authentication is required.
Attack surface
Reachable over the network via HTTP requests to /RestAPI endpoints and the ImportTechnicians Struts action; the CVSS vector shows AV:N/AC:L/PR:N/UI:N, so no authentication or user interaction is needed.
Exploitation
CISA added it to KEV on 2021-12-01 with a 2021-12-15 due date, and EPSS shows a 30-day probability of 0.93298 (99.8th percentile). Public exploit code is referenced by Packet Storm, and CISA records no known ransomware campaign use.
What to do
- Apply the vendor patches to move ServiceDesk Plus to 11306 or later, ServiceDesk Plus MSP to 10530 or later, and SupportCenter Plus to 11014 or later.
- If patching cannot be done immediately, restrict network access to the affected instances and block external reachability of /RestAPI and Struts endpoints.
- Place the products behind a reverse proxy or WAF with rules targeting the /RestAPI and ImportTechnicians paths.
- Audit the affected hosts for signs of compromise and rotate credentials and secrets stored on or reachable from them.
- Track the CISA KEV due date and confirm remediation before it lapses.
Detection
- Monitor web logs for requests to /RestAPI paths and ImportTechnicians actions, especially from unexpected source IPs.
- Alert on unexpected child processes spawned by the ManageEngine service (for example cmd.exe, powershell.exe, or shell interpreters).
- Review file system and application logs for new or modified files in web-accessible directories and for unusual technician account creation.
- Correlate outbound network connections from the ManageEngine host to unknown destinations.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-44077 to the Known Exploited Vulnerabilities catalog on 1 December 2021 as "Zoho ManageEngine ServiceDesk Plus Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 15 December 2021.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2021-44077 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-44077), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.