Fixed Intel

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Deadline: Dec 15, 2021

CVE-2021-44077

High
EPSS 94.3%CISA KEV
Zoho/ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus

Description

Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution

EPSS — Exploit Probability

94.3%

Higher than 99.9% of all CVEs

Required Action

https://nvd.nist.gov/vuln/detail/CVE-2021-44077

Risk Assessment

HIGH
In CISA KEV
High EPSS

Details

Severity
High
EPSS
94.3%
CISA KEV
Yes
Ransomware
Unknown
Articles
0

Timeline

Published

Dec 1, 2021

Added to KEV

Dec 1, 2021

Remediation Due

Dec 15, 2021

Affected Product

Zoho

ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus

View all Zoho CVEs