Sceawere

Vulnerability Detail

CVE-2026-74849UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

ADSelfService Plus GINA RCE

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
3h ago
Vendor
Zohocorp
Product
ManageEngine ADSelfService Plus
Attack Type
CWE-78 Improper neutralization of special elements used in an OS command ('OS command injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to a remote code execution vulnerability in the GINA client.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-09-22T12:17:14.007Z",
  "pubdate": "2026-09-22T12:17:14.007Z",
  "executiveSummary": "ManageEngine ADSelfService Plus prior to build 7001 contains a critical Remote Code Execution (RCE) vulnerability located within its GINA (Graphical Identification and Authentication) client component.\nThis vulnerability allows an unauthenticated, remote attacker to execute arbitrary code with elevated system privileges on the host machine where the GINA agent is installed.\nThe flaw stems from improper handling of data within the GINA client, which facilitates authentication processes at the Windows login screen.\nSuccessful exploitation results in full system compromise, enabling the attacker to bypass authentication mechanisms, deploy malware, exfiltrate sensitive credentials, or move laterally throughout the network.\nGiven the nature of the GINA client, which operates at the pre-logon phase of the Windows operating system, the risk profile is extremely high.\nImmediate mitigation is required as this vulnerability can be leveraged to gain persistence and complete control over the affected Windows infrastructure.",
  "technicalDetails": "The vulnerability resides within the GINA client component of ManageEngine ADSelfService Plus, which is deployed to end-user workstations to facilitate password self-service functionality directly from the Windows login screen.\nThe root cause is an insecure implementation in the data processing logic of the GINA client module. Specifically, the client fails to properly validate and sanitize input processed during the authentication handshake or communication phase between the client-side component and the ADSelfService Plus server.\nThe GINA client runs in the context of the Local System account, which is the highest privilege level on a Windows host. Because the component interacts with the Windows Logon process (Winlogon.exe), any memory corruption or injection vulnerability in this module inherently runs with System-level authority.\nThe exploitation flow typically begins with the attacker targeting the communication channel used by the GINA client. By sending specially crafted network requests or manipulating the data stream expected by the client, an attacker can trigger an unexpected execution path or buffer overflow condition. Due to the lack of sufficient integrity checks on the incoming data, the attacker can hijack the control flow of the GINA client process.\nOnce the attacker successfully redirects the instruction pointer or overwrites critical memory structures, they can inject arbitrary malicious payloads. Because the GINA client is a part of the Windows authentication subsystem, the malicious payload gains immediate System-level privileges without requiring an existing user session or legitimate credentials.\nThe impact of this RCE is total system compromise. Post-exploitation activities may include, but are not limited to, the installation of persistent backdoors, credential harvesting via LSASS memory dumping, or the deployment of ransomware. The attacker effectively bypasses standard OS security boundaries because the exploit occurs within a trusted component that is active before any user has even authenticated to the operating system.\nThis vulnerability affects all ADSelfService Plus builds prior to 7001. The exploit does not require the attacker to have valid domain credentials, provided they have network-level reach to the target systems where the GINA client is actively deployed."
}
CVE-2026-74849: ADSelfService Plus GINA RCE (CRITICAL Severity, CVSS: 9.8) | Sceawere