← Back to CVE List

CVE-2019-19034

Published: 2020-03-23T17:15Z
Last Modified: 2024-11-21T04:34Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Zoho ManageEngine Asset Explorer 6.5 does not validate the System Center Configuration Manager (SCCM) database username when dynamically generating a command to schedule scans for SCCM. This allows an attacker to execute arbitrary commands on the AssetExplorer Server with NT AUTHORITY/SYSTEM privileges. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt