ManageEngine has fixed a critical remote code execution vulnerability in ADSelfService Plus that could allow an unauthenticated attacker to run code as NT AUTHORITY\SYSTEM through a Windows device’s login screen. The flaw, tracked as CVE-2026-74849, affects the product’s GINA client in builds 7000 and earlier. Organizations should upgrade to build 7001 or later immediately. The issue resides in the GINA client, a component that places ADSelfService Plus password-reset and account-unlock functions directly on the Windows logon screen. It presents these functions in an embedded kiosk-style browser before a user signs in, allowing employees to reset passwords or unlock accounts without reaching the Windows desktop. Critical...
Read the full article at the source.
Comments (0)
No comments yet. Be the first to comment!