A PoC exploit code for the unauthenticated remote code execution vulnerability CVE-2022-47966 in Zoho ManageEngine will be released soon.
The CVE-2022-47966 flaw is an unauthenticated remote code execution vulnerability that impacts multiple Zoho products with SAML SSO enabled in the ManageEngine setup. The issue also impacts products that had the feature enabled in the past.
The root cause of the problem is that ManageEngine products use an outdated third-party dependency, Apache Santuario.
“This vulnerability allows an unauthenticated adversary to execute arbitrary code when the above SAML SSO criteria is met.” reads the advisory.
Researchers from Horizon3 Attack Team announced last week the developed of a PoC exploit code that they plan to release soon along with technical details of the flaw.
Users of Zoho ManageEngine are urged to address their installs immediately, before the release of (PoC) exploit code that could be exploited by threat actors in the wild.