Sceawere
Vulnerability Detail
CVE-2026-74849UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
ADSelfService Plus GINA RCE
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.8
- Creation Date
- 3h ago
- Vendor
- Zohocorp
- Product
- ManageEngine ADSelfService Plus
- Attack Type
- CWE-78 Improper neutralization of special elements used in an OS command ('OS command injection')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to a remote code execution vulnerability in the GINA client.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.8",
"pubDate": "2026-09-22T12:17:14.007Z",
"pubdate": "2026-09-22T12:17:14.007Z",
"executiveSummary": "ManageEngine ADSelfService Plus prior to build 7001 contains a critical Remote Code Execution (RCE) vulnerability located within its GINA (Graphical Identification and Authentication) client component.\nThis vulnerability allows an unauthenticated, remote attacker to execute arbitrary code with elevated system privileges on the host machine where the GINA agent is installed.\nThe flaw stems from improper handling of data within the GINA client, which facilitates authentication processes at the Windows login screen.\nSuccessful exploitation results in full system compromise, enabling the attacker to bypass authentication mechanisms, deploy malware, exfiltrate sensitive credentials, or move laterally throughout the network.\nGiven the nature of the GINA client, which operates at the pre-logon phase of the Windows operating system, the risk profile is extremely high.\nImmediate mitigation is required as this vulnerability can be leveraged to gain persistence and complete control over the affected Windows infrastructure.",
"technicalDetails": "The vulnerability resides within the GINA client component of ManageEngine ADSelfService Plus, which is deployed to end-user workstations to facilitate password self-service functionality directly from the Windows login screen.\nThe root cause is an insecure implementation in the data processing logic of the GINA client module. Specifically, the client fails to properly validate and sanitize input processed during the authentication handshake or communication phase between the client-side component and the ADSelfService Plus server.\nThe GINA client runs in the context of the Local System account, which is the highest privilege level on a Windows host. Because the component interacts with the Windows Logon process (Winlogon.exe), any memory corruption or injection vulnerability in this module inherently runs with System-level authority.\nThe exploitation flow typically begins with the attacker targeting the communication channel used by the GINA client. By sending specially crafted network requests or manipulating the data stream expected by the client, an attacker can trigger an unexpected execution path or buffer overflow condition. Due to the lack of sufficient integrity checks on the incoming data, the attacker can hijack the control flow of the GINA client process.\nOnce the attacker successfully redirects the instruction pointer or overwrites critical memory structures, they can inject arbitrary malicious payloads. Because the GINA client is a part of the Windows authentication subsystem, the malicious payload gains immediate System-level privileges without requiring an existing user session or legitimate credentials.\nThe impact of this RCE is total system compromise. Post-exploitation activities may include, but are not limited to, the installation of persistent backdoors, credential harvesting via LSASS memory dumping, or the deployment of ransomware. The attacker effectively bypasses standard OS security boundaries because the exploit occurs within a trusted component that is active before any user has even authenticated to the operating system.\nThis vulnerability affects all ADSelfService Plus builds prior to 7001. The exploit does not require the attacker to have valid domain credentials, provided they have network-level reach to the target systems where the GINA client is actively deployed."
}