Vulnerability Details CVE-2021-42954
                Zoho Remote Access Plus Server Windows Desktop Binary fixed from 10.1.2121.1 is affected by incorrect access control. The installation directory is vulnerable to weak file permissions by allowing full control for Windows Everyone user group (non-admin or any guest users), thereby allowing privilege escalation, unauthorized password reset, stealing of sensitive data, access to credentials in plaintext, access to registry values, tampering with configuration files, etc.
                
                    Exploit prediction scoring system (EPSS) score
                    
                        
                            EPSS Score 0.0
                        
                    
                    
                        
                            EPSS Ranking 12.0%
                        
                    
                 
                
                    CVSS Severity
                    
                        
                            CVSS v3 Score 7.8
                        
                    
                    
                        
                            CVSS v2 Score 4.6
                        
                    
                 
                
                
                
                    
                
                
                    
                        Products affected by CVE-2021-42954
                        
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:zohocorp:manageengine_remote_access_plus:-
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:zohocorp:manageengine_remote_access_plus:10.0.252
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:zohocorp:manageengine_remote_access_plus:10.0.253
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:zohocorp:manageengine_remote_access_plus:10.0.254
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:zohocorp:manageengine_remote_access_plus:10.0.255
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:zohocorp:manageengine_remote_access_plus:10.0.256
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:zohocorp:manageengine_remote_access_plus:10.0.257
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:zohocorp:manageengine_remote_access_plus:10.0.258
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:zohocorp:manageengine_remote_access_plus:10.0.259
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:zohocorp:manageengine_remote_access_plus:10.0.415
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:zohocorp:manageengine_remote_access_plus:10.0.416
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:zohocorp:manageengine_remote_access_plus:10.0.421
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:zohocorp:manageengine_remote_access_plus:10.0.422
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:zohocorp:manageengine_remote_access_plus:10.0.428
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:zohocorp:manageengine_remote_access_plus:10.0.430
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:zohocorp:manageengine_remote_access_plus:10.0.431
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:zohocorp:manageengine_remote_access_plus:10.0.432
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:zohocorp:manageengine_remote_access_plus:10.0.433
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:zohocorp:manageengine_remote_access_plus:10.0.434
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:zohocorp:manageengine_remote_access_plus:10.0.435
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:zohocorp:manageengine_remote_access_plus:10.0.436
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:zohocorp:manageengine_remote_access_plus:10.0.440
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:zohocorp:manageengine_remote_access_plus:10.0.447
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:zohocorp:manageengine_remote_access_plus:10.0.448
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:zohocorp:manageengine_remote_access_plus:10.0.450
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:zohocorp:manageengine_remote_access_plus:10.0.451
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:zohocorp:manageengine_remote_access_plus:10.0.452
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:zohocorp:manageengine_remote_access_plus:10.0.453
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:zohocorp:manageengine_remote_access_plus:10.0.454
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:zohocorp:manageengine_remote_access_plus:10.0.465
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:zohocorp:manageengine_remote_access_plus:10.0.466
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:zohocorp:manageengine_remote_access_plus:10.0.468
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:zohocorp:manageengine_remote_access_plus:10.0.469
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:zohocorp:manageengine_remote_access_plus:10.0.472
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:zohocorp:manageengine_remote_access_plus:10.0.473
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:zohocorp:manageengine_remote_access_plus:10.0.476
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:zohocorp:manageengine_remote_access_plus:10.1.2119.1
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:o:microsoft:windows:-