Zoho ManageEngine ADSelfService Plus is a self-service password management and single sign-on solution used by IT administrators to allow users to reset passwords, unlock accounts, and manage profiles without helpdesk intervention. It is deployed across enterprises to reduce support costs and enhance security through features like multi-factor authentication and directory integration.
CVE-2021-40539 is a critical authentication bypass vulnerability in the REST API of ADSelfService Plus versions up to 6113. The flaw arises from improper validation of user-supplied input during authentication, allowing an unauthenticated attacker to bypass security checks and execute arbitrary code on the server.
Specifically, the vulnerability exists in the REST API endpoint used for user authentication. By sending specially crafted requests, an attacker can manipulate the authentication process to gain unauthorized access and then execute commands via the product's built-in scripting capabilities.
If exploited, an attacker can achieve remote code execution with system-level privileges, leading to full compromise of the affected server. This can result in data theft, ransomware deployment, lateral movement within the network, and complete disruption of operations, posing severe risks to business continuity and data integrity.
- Upgrade Zoho ManageEngine ADSelfService Plus to version 6114 or later immediately.
- Apply the official patch provided by Zoho for CVE-2021-40539.
- Restrict network access to the ADSelfService Plus server using firewalls and VPNs.
- Enable multi-factor authentication (MFA) for all administrative accounts.
- Monitor logs for suspicious REST API requests and unauthorized access attempts.
- Implement web application firewall (WAF) rules to block exploitation patterns.
- Conduct a thorough security audit to identify any post-exploitation activity.
- Ensure regular backups are taken and stored offline to aid recovery.
Get AI-powered remediation steps tailored to your asset.
Try AI Solutions →