CVE-2025-5494
BaseFortify
Publication date: 2025-09-25
Last updated on: 2025-10-22
Assigner: ManageEngine
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| zohocorp | manageengine_endpoint_central | to 11.4.2500.26 (exc) |
| zohocorp | manageengine_endpoint_central | From 11.4.2508.01 (inc) to 11.4.2508.14 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-269 | The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
CVE-2025-5494 is a privilege escalation vulnerability in the Zoho ManageEngine Endpoint Central agent. It occurs because the agent improperly manages privileges during a patch scan, specifically by deleting privileged files. An attacker with local access can exploit this flaw to elevate their privileges to the SYSTEM level, gaining higher control over the affected system. [1]
How can this vulnerability impact me? :
This vulnerability can allow an attacker with local access to escalate their privileges to SYSTEM level on the affected machine. This means the attacker could gain full control over the system, potentially leading to unauthorized actions, data manipulation, or disruption of services. Although the severity is rated low, the impact of SYSTEM-level access can be significant depending on the environment. [1]
What immediate steps should I take to mitigate this vulnerability?
To mitigate CVE-2025-5494, immediately upgrade ZohoCorp ManageEngine Endpoint Central to the fixed versions 11.4.2500.26 or 11.4.2508.14. The upgrade process involves logging into the Endpoint Central console, clicking the current build number to find the latest applicable build, downloading the Patch Package Manager (PPM), and applying the update. This will address the privilege escalation vulnerability caused by improper privilege management in the agent setup. [1]