module

ManageEngine ServiceDesk Plus CVE-2021-44077

Disclosed
2021-09-16
Created
2021-12-28

Description

This module exploits CVE-2021-44077, an unauthenticated remote code
execution vulnerability in ManageEngine ServiceDesk Plus, to upload an
EXE (msiexec.exe) and execute it as the SYSTEM account.

Note that build 11305 is vulnerable to the authentication bypass but
not the file upload. The module will check for an exploitable build.

Authors

wvu wvu@metasploit.com
Y4er

Platform

Windows

Architectures

x86, x64

Module Options

To display the available options, load the module within the Metasploit console and run the commands ‘show options’ or ‘show advanced’:


msf > use exploit/windows/http/manageengine_servicedesk_plus_cve_2021_44077
msf exploit(manageengine_servicedesk_plus_cve_2021_44077) > show targets
...targets...
msf exploit(manageengine_servicedesk_plus_cve_2021_44077) > set TARGET < target-id >
msf exploit(manageengine_servicedesk_plus_cve_2021_44077) > show options
...show and set options...
msf exploit(manageengine_servicedesk_plus_cve_2021_44077) > exploit

Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.