ManageEngine ADManager Plus
cpe:2.3:a:zohocorp:manageengine_admanager_plus:*:*:*:*:*:*:*
- <= 8022
A vulnerability allowing NTLM hash exposure has been identified in ManageEngine ADManager Plus versions prior to 8025. This issue affects the service account configured in ADManager Plus, exposing its NTLM hash to authorized technicians. The vulnerability is exploitable only by technicians with the 'Impersonate as Admin' option enabled.
Technicians with the 'Impersonate as Admin' option enabled could retrieve the NTLM hash of a service account, potentially leading to unauthorized access or privilege escalation.
Users are advised to update their ADManager Plus instance to the latest build by installing the available service pack.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.