CVE detail
CVE-2022-47966
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT features, by design in that version, make the application responsible for certain security protections, and the ManageEngine applications did not provide those protections. This affects Access Manager Plus before 4308, Active Directory 360 before 4310, ADAudit Plus before 7081, ADManager Plus before 7162, ADSelfService Plus before 6211, Analytics Plus before 5150, Application Control Plus before 10.1.2220.18, Asset Explorer before 6983, Browser Security Plus before 11.1.2238.6, Device Control Plus before 10.1.2220.18, Endpoint Central before 10.1.2228.11, Endpoint Central MSP before 10.1.2228.11, Endpoint DLP before 10.1.2137.6, Key Manager Plus before 6401, OS Deployer before 1.1.2243.1, PAM 360 before 5713, Password Manager Pro before 12124, Patch Manager Plus before 10.1.2220.18, Remote Access Plus before 10.1.2228.11, Remote Monitoring and Management (RMM) before 10.1.41. ServiceDesk Plus before 14004, ServiceDesk Plus MSP before 13001, SupportCenter Plus before 11026, and Vulnerability Manager Plus before 10.1.2220.18. Exploitation is only possible if SAML SSO has ever been configured for a product (for some products, exploitation requires that SAML SSO is currently active).
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 5.7
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
40 source links · newest first
Most of the top frequently exploited vulnerabilities in 2023 were initially exploited as zero-days, according to data from government agencies.
newswww.securityweek.comNov 13, 2024, 3:46 PMA threat actor has been compromising the hybrid cloud environments of US organizations in multiple sectors.
newswww.securityweek.comSep 30, 2024, 10:05 AMIran-linked Peach Sandstorm APT is behind password spray attacks against thousands of organizations globally between February and July 2023. Microsoft researchers observed a series of password spray attacks conducted by Iran nation-state actors as part of a campaign named Peach Sandstorm (aka Holmium, APT33, Elfin, and Magic Hound). The APT33 group has been around since at least […]
newssecurityaffairs.comSep 16, 2023, 1:36 PMAn Iranian state-operated cyberespionage group has launched password spray attacks against thousands of organizations this year in an attempt to establish persistence into their environments, move laterally, and collect useful intelligence. The targeted organizations were primarily from the satellite, defense, and pharmaceuticals sectors and spanned different geographies. Microsoft tracks the group as Peach Sandstorm, but […]
newswww.csoonline.comSep 15, 2023, 9:02 PM- 11th September – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 11th September, please download our Threat_Intelligence Bulletin. TOP ATTACKS AND BREACHES Check Point warns of a recent Email phishing campaign abusing the data visualization tool – Google Looker Studio. Attackers use the tool to send slideshow emails to victims from official Google accounts, instructing […]
vendorresearch.checkpoint.comSep 11, 2023, 4:34 PM - Nation-state actors exploit Fortinet FortiOS SSL-VPN and Zoho ManageEngine ServiceDesk Plus, CISA warnsSecurity Affairs
U.S. CISA warned that nation-state actors are exploiting flaws in Fortinet FortiOS SSL-VPN and Zoho ManageEngine ServiceDesk Plus. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that nation-state actors are exploiting security vulnerabilities in Fortinet FortiOS SSL-VPN and Zoho ManageEngine ServiceDesk Plus. The US agency has detected the presence of indicators of compromise (IOCs) […]
newssecurityaffairs.comSep 8, 2023, 12:06 PM APTs exploited vulnerabilities in Zoho ManageEngine and Fortinet VPNs to hack an aerospace organization in early January 2023.
newswww.securityweek.comSep 8, 2023, 9:13 AMHere’s an overview of some of last week’s most interesting news, articles, interviews and videos: Network detection and response in the modern era In this Help Net Security interview, David Gugelmann, CEO at Exeon, sheds light on the current cyber threats and their challenges for network security. He discusses the role of Network Detection and Response (NDR) solutions that leverage machine learning algorithms to improve threat detection and streamline incident response. Lazarus Group exploited ManageEngine … More →
newswww.helpnetsecurity.comAug 27, 2023, 8:00 AMOne of North Korea’s most prominent cyberespionage groups has been using two new remote access trojans (RATs) in attack campaigns this year, researchers warn. One of the operations targeted internet backbone infrastructure and healthcare organizations from Europe and the United States. “Lazarus Group remains highly active, with this being their third documented campaign in less […]
newswww.csoonline.comAug 25, 2023, 8:30 PMNorth Korea-linked Lazarus Group exploited a ManageEngine vulnerability to compromise an internet backbone infrastructure provider.
newswww.securityweek.comAug 25, 2023, 12:47 PM- Lazarus Group exploited ManageEngine vulnerability to target critical infrastructureHelp Net Security
North Korean state-sponsored hackers Lazarus Group have been exploiting a ManageEngine ServiceDesk vulnerability (CVE-2022-47966) to target internet backbone infrastructure and healthcare institutions in Europe and the US. The group leveraged the vulnerability to deploy QuiteRAT, downloaded from an IP address previously associated with the Lazarus hacking group (aka APT38). QuiteRAT CVE-2022-47966 has been patched in mid-January 2023, and soon after a PoC exploit for it was publicly released and exploitation attempts started in earnest. The … More →
newswww.helpnetsecurity.comAug 25, 2023, 12:18 PM - Lazarus APT exploits Zoho ManageEngine flaw to target an Internet backbone infrastructure providerSecurity Affairs
The North Korea-linked Lazarus group exploits a critical flaw in Zoho ManageEngine ServiceDesk Plus to deliver the QuiteRAT malware. The North Korea-linked APT group Lazarus has been exploiting a critical vulnerability, tracked as CVE-2022-47966, in Zoho’s ManageEngine ServiceDesk in attacks aimed at the Internet backbone infrastructure provider and healthcare organizations. The state-sponsored hackers targeted entities […]
newssecurityaffairs.comAug 24, 2023, 5:50 PM A cyberespionage group believed to be associated with the Iranian government has been infecting Microsoft Exchange Servers with a new malware implant dubbed BellaCiao that acts as a dropper for additional payloads. The malware uses DNS queries to receive commands from attackers encoded into IP addresses. According to researchers from Bitdefender, the attackers appear to […]
newswww.csoonline.comApr 26, 2023, 9:28 PMA subgroup of Iran-linked APT Phosphorus (Mint Sandstorm) has started to quickly adopt PoC exploit code targeting vulnerabilities in internet-facing applications.
newswww.securityweek.comApr 19, 2023, 10:08 AM- Security Affairs newsletter Round 408 by Pierluigi PaganiniSecurity Affairs
A new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from Security Affairs are free for you in your email box. If you want to also receive for free the newsletter with the international press subscribe here. Clasiopa group targets materials research in Asia CERT of Ukraine says Russia-linked APT backdoored multiple govt […]
newssecurityaffairs.comFeb 26, 2023, 11:05 AM Experts warn of threat actors actively exploiting the critical CVE-2022-47966 (CVSS score: 9.8) flaw in Zoho ManageEngine. Multiple threat actors are actively exploiting the Zoho ManageEngine CVE-2022-47966 (CVSS score: 9.8) in attacks in the wild, Bitdefender Labs reported. “Starting on January 20 2023, Bitdefender Labs started to notice a global increase in attacks using the ManageEngine exploit CVE-2022-47966.” reads the […]
newssecurityaffairs.comFeb 24, 2023, 11:01 AM- Security Affairs newsletter Round 404 by Pierluigi PaganiniSecurity Affairs
A new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from Security Affairs free for you in your email box. If you want to also receive for free the newsletter with the international press subscribe here. Copycat Criminals mimicking Lockbit gang in northern Europe Sandworm APT targets Ukraine with new SwiftSlicer wiper […]
newssecurityaffairs.comJan 29, 2023, 3:16 PM - CISA added Zoho ManageEngine RCE (CVE-2022-47966) to its Known Exploited Vulnerabilities CatalogSecurity Affairs
US CISA added the Zoho ManageEngine RCE vulnerability CVE-2022-47966 to its Known Exploited Vulnerabilities Catalog. The US CISA added the Zoho ManageEngine remote code execution flaw (CVE-2022-47966) to its Known Exploited Vulnerabilities Catalog. The CVE-2022-47966 flaw is an unauthenticated remote code execution vulnerability that impacts multiple Zoho products with SAML SSO enabled in the ManageEngine setup. The […]
newssecurityaffairs.comJan 24, 2023, 11:03 AM Users of on-premises deployments of Zoho ManageEngine products should make sure they have patches applied for a critical remote code execution vulnerability that attackers have now started exploiting in the wild. Technical details about the flaw along with a proof-of-concept exploit was released late last week, which will allow more attackers to add this exploit […]
newswww.csoonline.comJan 23, 2023, 9:30 PM- 23rd January – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 23rd January, please download our Threat_Intelligence Bulletin TOP ATTACKS AND BREACHES The fast food brand ‘Yum! Brands’, operator of leading fast food restaurants including KFC, Pizza Hut and Taco Bell, has been targeted by a ransomware attack. The attack lead to the temporary closure […]
vendorresearch.checkpoint.comJan 23, 2023, 1:50 PM - Security Affairs newsletter Round 403 by Pierluigi PaganiniSecurity Affairs
A new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from Security Affairs free for you in your email box. If you want to also receive for free the newsletter with the international press subscribe here. The Irish DPC fined WhatsApp €5.5M for violating GDPR Around 19,500 end-of-life Cisco routers are exposed […]
newssecurityaffairs.comJan 22, 2023, 10:38 AM - Week in review: Critical git vulnerabilities, increasingly malicious Google Search adsHelp Net Security
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Cacti servers under attack by attackers exploiting CVE-2022-46169 If you’re running the Cacti network monitoring solution and you haven’t updated it since early December, now is the time to do it to foil attackers exploiting a critical command injection flaw (CVE-2022-46169). CircleCI breach post-mortem: Attackers got in by stealing engineer’s session cookie The attackers who pulled off the recent breach … More →
newswww.helpnetsecurity.comJan 22, 2023, 9:30 AM Organizations are being compromised in attacks exploiting a recently patched Zoho ManageEngine vulnerability.
newswww.securityweek.comJan 20, 2023, 4:37 PMResearchers released Proof-of-concept exploit code for remote code execution flaw CVE-2022-47966 impacting multiple Zoho ManageEngine products. The CVE-2022-47966 flaw is an unauthenticated remote code execution vulnerability that impacts multiple Zoho products with SAML SSO enabled in the ManageEngine setup. The issue also impacts products that had the feature enabled in the past. The root cause of […]
newssecurityaffairs.comJan 19, 2023, 8:51 PMIntroduction On January 10, 2023, ManageEngine released a security advisory for CVE-2022-47966 (discovered by Khoadha of Viettel Cyber Security) affecting a wide range of products. The vulnerability allows an attacker to gain remote code execution by issuing a HTTP POST request containing a malicious SAML response. This vulnerability is a result of using an outdated […]
exploithorizon3.aiJan 19, 2023, 1:10 PMNo excerpt available.
Mitigationwww.cisa.govJan 18, 2023, 6:15 PM- https://www.manageengine.com/security/advisory/CVE/cve-2022-47966.htmlwww.manageengine.com
No excerpt available.
Vendor Advisorywww.manageengine.comJan 18, 2023, 6:15 PM No excerpt available.
Exploitwww.horizon3.aiJan 18, 2023, 6:15 PMNo excerpt available.
Mitigationwww.cisa.govJan 18, 2023, 6:15 PMNo excerpt available.
Exploitgithub.comJan 18, 2023, 6:15 PMNo excerpt available.
Exploitgithub.comJan 18, 2023, 6:15 PM- https://blog.viettelcybersecurity.com/saml-show-stopper/blog.viettelcybersecurity.com
No excerpt available.
Exploitblog.viettelcybersecurity.comJan 18, 2023, 6:15 PM No excerpt available.
Exploitattackerkb.comJan 18, 2023, 6:15 PM- http://packetstormsecurity.com/files/170943/Zoho-ManageEngine-Endpoint-Central-MSP-10.1.2228.10-Remote-Code-Execution.htmlpacketstormsecurity.com
No excerpt available.
Exploitpacketstormsecurity.comJan 18, 2023, 6:15 PM - http://packetstormsecurity.com/files/170925/ManageEngine-ADSelfService-Plus-Unauthenticated-SAML-Remote-Code-Execution.htmlpacketstormsecurity.com
No excerpt available.
Exploitpacketstormsecurity.comJan 18, 2023, 6:15 PM - http://packetstormsecurity.com/files/170882/Zoho-ManageEngine-ServiceDesk-Plus-14003-Remote-Code-Execution.htmlpacketstormsecurity.com
No excerpt available.
Exploitpacketstormsecurity.comJan 18, 2023, 6:15 PM - Patch your Zoho ManageEngine instance immediately! PoC Exploit for CVE-2022-47966 will be released soonSecurity Affairs
A PoC exploit code for the unauthenticated remote code execution vulnerability CVE-2022-47966 in Zoho ManageEngine will be released soon. The CVE-2022-47966 flaw is an unauthenticated remote code execution vulnerability that impacts multiple Zoho products with SAML SSO enabled in the ManageEngine setup. The issue also impacts products that had the feature enabled in the past. The […]
newssecurityaffairs.comJan 17, 2023, 1:51 PM - PoC for critical ManageEngine bug to be released, so get patching! (CVE-2022-47966)Help Net Security
If your enterprise is running ManageEngine products that were affected by CVE-2022-47966, check now whether they’ve been updated to a non-vulnerable version because Horizon3.ai will be releasing technical details and a PoC exploit this week. GreyNoise has yet to detect in-the-wild exploitation attempts, but you better believe they are coming. “The vulnerability is easy to exploit and a good candidate for attackers to ‘spray and pray’ across the Internet,” vulnerability researcher James Horseman opined. About … More →
newswww.helpnetsecurity.comJan 17, 2023, 12:39 PM Researchers tracking a remote code execution vulnerability in Zoho’s ManageEngine products are warning organizations to brace for “spray and pray” attacks across the internet.
newswww.securityweek.comJan 16, 2023, 11:37 AM- ManageEngine CVE-2022-47966 IOCsHorizon3.ai
Introduction The recent ManageEngine CVE-2022-47966 is a pre-authentication remote code execution vulnerability. Depending on the specific ManageEngine product, this vulnerability is exploitable if SAML single-sign-on is enabled or has ever been enabled. ManageEngine products are some of the most widely used across enterprises and perform business functions such as authentication, authorization, and identity management. Given the nature […]
exploithorizon3.aiJan 13, 2023, 3:45 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
1 repository references · best confidence 0.80 · max 7 stars
- sh4den/CVE-2022-47966Medium confidencegithubDiscovery source unavailable7 starsDiscovered Jul 9, 2026, 1:19 AM
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2023-6105CVSS 5.5 · Medium
An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host…
- CVE-2019-12133CVSS 7.8 · High
Multiple Zoho ManageEngine products suffer from local privilege escalation due to improper permissions for the %SYSTEMDRIVE%\ManageEngine directory and its sub-folders. Moreover,…
- CVE-2023-35785CVSS 8.1 · High
Zoho ManageEngine Active Directory 360 versions 4315 and below, ADAudit Plus 7202 and below, ADManager Plus 7200 and below, Asset Explorer 6993 and below and 7xxx 7002 and below,…
- CVE-2023-29443CVSS 4.9 · Medium
Zoho ManageEngine ServiceDesk Plus before 14105, ServiceDesk Plus MSP before 14200, SupportCenter Plus before 14200, and AssetExplorer before 6989 allow SDAdmin attackers to condu…
- CVE-2023-26601CVSS 7.5 · High
Zoho ManageEngine ServiceDesk Plus through 14104, Asset Explorer through 6987, ServiceDesk Plus MSP before 14000, and Support Center Plus before 14000 allow Denial-of-Service (DoS…
- CVE-2023-26600CVSS 6.5 · Medium
ManageEngine ServiceDesk Plus through 14104, ServiceDesk Plus MSP through 14000, Support Center Plus through 14000, and Asset Explorer through 6987 allow privilege escalation via…