Back to Database
Status published
Critical
CVE-2021-42099
Zoho ManageEngine M365 Manager Plus before 4421 is vulnerable to...
Vulnerability Description
Zoho ManageEngine M365 Manager Plus before 4421 is vulnerable to file-upload remote code execution.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-42099
Credits & Attribution
No credits recorded in the NVD database.
References
More from zohocorp
View All →CVE-2022-48362
Zoho ManageEngine Desktop Central and Desktop Central MSP before 10.1.2137.2...
Unknown
0
CVE-2022-47966
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through...
Unknown
0
CVE-2022-47578
An issue was discovered in the endpoint protection agent in...
High
7.1
CVE-2022-47577
An issue was discovered in the endpoint protection agent in...
High
7.1
CVE-2022-47523
Zoho ManageEngine Access Manager Plus before 4309, Password Manager Pro...
Unknown
0
Affected Vendor
zohocorp
View all reports →Affected Software
manageengine m365 manager plus
Vulnerable Versions:
build_4000, build_4001, build_4002, build_4003, build_4004, build_4005, build_4007, build_4008, build_4009, build_4010, build_4011, build_4012, build_4013, build_4014, build_4100, build_4101, build_4102, build_4103, build_4104, build_4105, build_4106, build_4108, build_4109, build_4110, build_4111, build_4112, build_4113, build_4115, build_4116, build_4117, build_4118, build_4119, build_4200, build_4201, build_4202, build_4203, build_4204, build_4205, build_4206, build_4207, build_4208, build_4209, build_4210, build_4211, build_4212, build_4213, build_4214, build_4215, build_4216, build_4217, build_4218, build_4219, build_4220, build_4221, build_4222, build_4300, build_4301, build_4302, build_4303, build_4304, build_4305, build_4306, build_4308, build_4309, build_4310, build_4311, build_4312, build_4316, build_4317, build_4318, build_4319, build_4320, build_4321, build_4322, build_4324, build_4325, build_4327, build_4328, build_4329, build_4330, build_4331, build_4332, build_4333, build_4334, build_4335, build_4336, build_4400, build_4401, build_4402, build_4403, build_4406, build_4407, build_4408, build_4410, build_4411, build_4412, build_4413, build_4414, build_4415, build_4416, build_4417, build_4418, build_4419
Timeline
Official Publish:
November 30th, 2021
Last Modified:
August 4th, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.