Zohocorp’s ManageEngine has disclosed a critical vulnerability in its ADAudit Plus software during a significant cybersecurity development.
It’s a popular tool used for Active Directory auditing and reporting. The vulnerability, identified as CVE-2024-49574, exposes versions of ADAudit Plus prior to build 8123 to potential SQL injection attacks.
The security flaw, classified as high severity, specifically affects the reports module of ADAudit Plus.
This SQL injection vulnerability could allow an authenticated attacker to execute custom queries and gain unauthorized access to database table entries.
Experts at ManageEnigne observed that the potential for data breaches and system compromises makes this a serious concern for organizations relying on ADAudit Plus for their Active Directory management.
Are you from SOC/DFIR Teams? – Analyse Malware Files & Links with ANY.RUN -> Try for Free
The implications of this vulnerability are far-reaching. Authenticated adversaries could potentially exploit this flaw to:
Such capabilities in the hands of malicious actors pose significant risks to an organization’s data integrity and overall security posture.
ManageEngine has acted swiftly to address this vulnerability. A fix has been developed and is now available in ADAudit Plus build 8123, released on November 8, 2024. IT administrators and security professionals are strongly urged to update their ADAudit Plus installations to this latest version immediately.
To mitigate the risk, ManageEngine recommends the following steps:
For users running very old versions of ADAudit Plus, a staged upgrade process may be necessary. ManageEngine has provided detailed instructions for various version ranges to ensure a smooth transition to the latest, secure build.
SQL injection vulnerabilities continue to be a significant threat vector, highlighting the need for ongoing vigilance in software development and maintenance.
Organizations using ManageEngine ADAudit Plus are advised to treat this update as a priority. The potential risks associated with CVE-2024-49574 underscore the importance of maintaining up-to-date software and regularly assessing system vulnerabilities. As cyber threats continue to evolve, staying current with security patches remains a crucial aspect of maintaining a strong cybersecurity posture.
Maximizing Cybersecurity ROI: Expert Tips for SME & MSP Leaders – Attend Free Webinar
Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…
The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…
CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…
Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…
You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…
Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…