Kryptovaluta-ticker:
sysadmin fra Cyber Security News

Critical ManageEngine Flaw Lets Attackers Gain SYSTEM Access Through Windows Login Screen

Abinaya
5 hours ago
4 Visninger
0 Kommentarer
Critical ManageEngine Flaw Lets Attackers Gain SYSTEM Access Through Windows Login Screen

ManageEngine has fixed a critical remote code execution vulnerability in ADSelfService Plus that could allow an unauthenticated attacker to run code as NT AUTHORITY\SYSTEM through a Windows device’s login screen. The flaw, tracked as CVE-2026-74849, affects the product’s GINA client in builds 7000 and earlier. Organizations should upgrade to build 7001 or later immediately. The issue resides in the GINA client, a component that places ADSelfService Plus password-reset and account-unlock functions directly on the Windows logon screen. It presents these functions in an embedded kiosk-style browser before a user signs in, allowing employees to reset passwords or unlock accounts without reaching the Windows desktop. Critical...

Læs hele artiklen hos kilden.

Deltag i diskussionen — kommenter, stem og del links.

Registrer
Var dette nyttigt?
Del:

Kommentarer (0)

Log venligst ind eller opret dig for at deltage i diskussionen

Ingen kommentarer ennå. Bli den første til å kommentere!