Cyber Resilience

CVE-2021-44515

Zohocorp Manageengine Desktop Central ≤ 10.1.2127.18

CISA KEVActive ExploitationEUVD ExploitedPublic PoC
Published
12 December 2021
Modified
31 October 2025
KEV Added
10 December 2021
Patch / advisory
CVSS Score v3.1 9.8
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.99 100.0th percentile
Risk Priority 97 floored blend · peak EPSS

Summary

CVE-2021-44515 is a critical-severity an unspecified weakness vulnerability in Zohocorp Manageengine Desktop Central. Its CVSS base score is 9.8 (Critical).

Operationally, ranked in the top 0.0% of CVEs by exploit likelihood; CISA has added it to the Known Exploited Vulnerabilities catalog; a public proof-of-concept is referenced.

Deeper analysis AI-assisted summary

Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.

Zoho ManageEngine Desktop Central is affected by an authentication bypass vulnerability that leads to remote code execution on the server. The flaw impacts Enterprise and MSP builds 10.1.2127.17 and earlier as well as builds 10.1.2128.0 through 10.1.2137.2.

Remote attackers with no credentials can exploit the issue over the network to bypass authentication and achieve arbitrary code execution on the server. The vulnerability carries a CVSS v3.1 score of 9.8 and was actively exploited in the wild in December 2021.

Vendor advisories direct customers to apply the listed updates, moving Enterprise or MSP builds 10.1.2127.17 and earlier to 10.1.2127.18 and builds 10.1.2128.0–10.1.2137.2 to 10.1.2137.3. CISA has added the CVE to its catalog of known exploited vulnerabilities, underscoring the urgency of patching.

EU & UK References

Vulnerability Data

Zoho ManageEngine Desktop Central is vulnerable to authentication bypass, leading to remote code execution on the server, as exploited in the wild in December 2021. For Enterprise builds 10.1.2127.17 and earlier, upgrade to 10.1.2127.18. For Enterprise builds 10.1.2128.0 through 10.1.2137.2,…

more

upgrade to 10.1.2137.3. For MSP builds 10.1.2127.17 and earlier, upgrade to 10.1.2127.18. For MSP builds 10.1.2128.0 through 10.1.2137.2, upgrade to 10.1.2137.3.

CWE(s)
KEV Date Added
10 December 2021

Related Threats

CVEs Like This One

CVE-2020-10189Same product: Zohocorp Manageengine Desktop Centralboth on KEV
CVE-2013-7390Same product: Zohocorp Manageengine Desktop Central
CVE-2023-4769Same product: Zohocorp Manageengine Desktop Central
CVE-2023-4768Same product: Zohocorp Manageengine Desktop Central
CVE-2023-4767Same product: Zohocorp Manageengine Desktop Central
CVE-2021-37415Same product class: network monitoring / SIEMboth on KEV
CVE-2022-28810Same product class: network monitoring / SIEMboth on KEV
CVE-2021-40539Same product class: network monitoring / SIEMboth on KEV
CVE-2022-47966Same product class: network monitoring / SIEMboth on KEV
CVE-2022-35405Same product class: network monitoring / SIEMboth on KEV

Affected Assets

zohocorp
manageengine desktop central
≤ 10.1.2127.18 · ≤ 10.1.2127.18 · 10.1.2128.0 — 10.1.2137.3

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References