LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-44077: Zoho ManageEngine ServiceDesk Plus Remote Code Execution Vulnerability

RBRecent Breaches Vulnerability Intelligence·Dec 1, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Dec 15, 2021
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-44077 to its Known Exploited Vulnerabilities catalog on Dec 1, 2021, with a federal patch deadline of Dec 15, 2021 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution

CVE-2021-44077 is an unauthenticated remote code execution vulnerability in Zoho ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP, and SupportCenter Plus. It allows an attacker who can reach the application over the network to run code on the host without logging in. Because these products often sit on internal networks and hold service-desk data, a successful exploit can give an attacker a foothold for further movement or data access. Public detail is limited to the CISA description; confirm exact build numbers and fixed releases against the vendor advisory.

How it works

The weakness is classified as CWE-306: Missing Authentication for Critical Function. In products of this class, a sensitive operation that should require a valid session or credential is reachable without any authentication check. An attacker who can send requests to the exposed service can invoke that function and achieve remote code execution on the underlying system. The CISA summary states the issue affects ServiceDesk Plus before build 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014; it does not publish exploit mechanics or proof-of-concept details. Defenders should treat any unauthenticated path that can lead to code execution as high risk and verify the precise attack surface in the vendor advisory rather than relying on third-party write-ups.

Am I affected? How to find it in your systems

These ManageEngine products are commonly deployed as on-premises or self-hosted service-desk and ITSM platforms, often reachable from internal networks and sometimes from the internet for remote support. Inventory steps:

How to remediate

Patch first. Apply the updates published by Zoho for the affected products exactly as directed in the vendor advisory and as required by CISA (“Apply updates per vendor instructions”). After upgrading:

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls:

These measures lower risk but do not replace the patch.

If your data may have been exposed

Actively exploited remote-code-execution flaws in service-desk platforms can lead to credential theft, lateral movement, and exposure of ticket and asset data. Ransomware use is not documented for this CVE in the supplied facts. If you suspect compromise, isolate the host, preserve logs and disk images, and follow your incident-response process. You can also run a free exposure scan of your email addresses against known breach data to see whether associated accounts have appeared in prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedZoho · ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus
WeaknessCWE-306
Added to CISA KEVDec 1, 2021
Federal patch deadlineDec 15, 2021
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities