Vulnerability record · CVE-2021-44515 · published 12 December 2021
CVE-2021-44515: Zoho ManageEngine Desktop Central authentication bypass to RCE
Zohocorp · Manageengine Desktop Central
Zoho ManageEngine Desktop Central contains an authentication bypass that allows an unauthenticated remote attacker to execute code on the server. It was exploited in the wild in December 2021, and the vendor has published fixed builds for both Enterprise and MSP editions.
Description
Zoho ManageEngine Desktop Central is vulnerable to authentication bypass, leading to remote code execution on the server, as exploited in the wild in December 2021. For Enterprise builds 10.1.2127.17 and earlier, upgrade to 10.1.2127.18. For Enterprise builds 10.1.2128.0 through 10.1.2137.2, upgrade to 10.1.2137.3. For MSP builds 10.1.2127.17 and earlier, upgrade to 10.1.2127.18. For MSP builds 10.1.2128.0 through 10.1.2137.2, upgrade to 10.1.2137.3.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable remote code execution with confirmed in-the-wild exploitation, KEV listing, and near-maximum EPSS probability.
What it is
Zoho ManageEngine Desktop Central contains an authentication bypass that allows an unauthenticated remote attacker to execute code on the server. It was exploited in the wild in December 2021, and the vendor has published fixed builds for both Enterprise and MSP editions.
Impact
An attacker gains unauthenticated remote code execution on the Desktop Central server, which typically holds broad administrative control over managed endpoints.
Attack surface
Reachable over the network via the Desktop Central web interface with no authentication and no user interaction, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The record does not specify the exact vulnerable endpoint or filter.
Exploitation
Listed in CISA KEV with a 2021-12-10 due date of 2021-12-24, and EPSS 30-day probability is 0.99871 (99.96th percentile). A vendor reference is tagged Exploit, and the description states it was exploited in the wild in December 2021.
What to do
- Upgrade Enterprise builds 10.1.2127.17 and earlier to 10.1.2127.18, and Enterprise builds 10.1.2128.0 through 10.1.2137.2 to 10.1.2137.3.
- Upgrade MSP builds 10.1.2127.17 and earlier to 10.1.2127.18, and MSP builds 10.1.2128.0 through 10.1.2137.2 to 10.1.2137.3.
- If patching cannot be done immediately, remove Desktop Central from direct internet exposure and restrict access to trusted management networks.
- Review the vendor advisory for the recommended filter configuration guidance referenced in the CVE-2021-44515 page.
- Treat the Desktop Central server as potentially compromised if it was internet-facing before patching and hunt for post-exploitation activity.
Detection
- Search web and proxy logs for requests to Desktop Central paths that bypass authentication, focusing on the December 2021 exploitation window and any later scanning.
- Monitor the Desktop Central server for unexpected child processes, web shells, or new files written by the application service account.
- Alert on outbound connections from the Desktop Central host to unfamiliar external addresses, which may indicate post-exploitation tooling.
- Audit Desktop Central logs and host telemetry for new administrative accounts or configuration changes made outside normal change windows.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-44515 to the Known Exploited Vulnerabilities catalog on 10 December 2021 as "Zoho Desktop Central Authentication Bypass Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 24 December 2021.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2021-44515 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-44515), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.