Vulnerability record · CVE-2022-40770 · published 23 November 2022
CVE-2022-40770: Zoho ManageEngine ServiceDesk Plus authenticated command injection
Zohocorp · Manageengine Servicedesk Plus
Zoho ManageEngine ServiceDesk Plus (and related MSP and SupportCenter Plus products) versions 13010 and prior contain an authenticated command injection flaw (CWE-77). A high-privileged user can inject OS commands through the application, which matters because such access can lead to full compromise of the server hosting the service desk platform.
Description
Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to authenticated command injection. This can be exploited by high-privileged users.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityAuthenticated command injection with high confidentiality, integrity and availability impact and very high EPSS, though it requires high privileges and is not in KEV.
What it is
Zoho ManageEngine ServiceDesk Plus (and related MSP and SupportCenter Plus products) versions 13010 and prior contain an authenticated command injection flaw (CWE-77). A high-privileged user can inject OS commands through the application, which matters because such access can lead to full compromise of the server hosting the service desk platform.
Impact
An attacker with high privileges gains remote code execution on the underlying host, with high impact to confidentiality, integrity and availability. This effectively turns administrative application access into control of the server.
Attack surface
The flaw is reachable over the network (AV:N) with no user interaction (UI:N), but requires high privileges (PR:H), so an attacker must already hold an administrative or similarly elevated account. No public exploit detail is provided beyond the vendor advisory.
Exploitation
Not listed in CISA KEV and no ransomware usage is documented, but EPSS is very high (0.813, ~99.6th percentile), indicating elevated predicted exploitation likelihood. All references are vendor advisories, so no public exploit code is confirmed in this record.
What to do
- Upgrade ServiceDesk Plus, ServiceDesk Plus MSP and SupportCenter Plus to a version later than 13010 per the vendor advisory.
- Restrict and audit high-privileged accounts; enforce least privilege and remove unused admin roles.
- Limit network exposure of the service desk web interface to trusted networks or VPN.
- Monitor and alert on unexpected child processes spawned by the application server.
- Review logs for anomalous command execution or administrative actions around the time of suspected abuse.
Detection
- Alert on OS process creation where the parent process is the ServiceDesk Plus application or its Java/web server process.
- Monitor for command shell or scripting interpreter launches (cmd.exe, powershell, /bin/sh) originating from the service desk service account.
- Audit administrative account activity for unusual command or configuration changes in ServiceDesk Plus logs.
- Correlate web requests to the service desk with subsequent suspicious process execution on the host.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://manageengine.com | Vendor Advisory |
| https://www.manageengine.com/products/service-desk/CVE-2022-40770.html | Vendor Advisory |
| https://manageengine.com | Vendor Advisory |
| https://www.manageengine.com/products/service-desk/CVE-2022-40770.html | Vendor Advisory |
Track CVE-2022-40770 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-40770), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.