Skip to main content
Mallory
CriticalCISA KEVExploited in the wildPublic exploit

Unauthenticated RCE in Zoho ManageEngine SAML SSO

IdentifiersCVE-2022-47966CWE-347Also known asmanageengine_cve_2022_47966

CVE-2022-47966 is an unauthenticated remote code execution vulnerability affecting multiple on-premises Zoho ManageEngine products, including ServiceDesk Plus and others, caused by use of Apache Santuario XML Security for Java (xmlsec) 1.4.1 in SAML processing. In the affected implementations, crafted SAMLResponse XML sent to a ManageEngine SAML endpoint can trigger unsafe XSLT processing because xmlsec 1.4.1 leaves critical security protections to the application, and the ManageEngine products did not enforce those protections. Public reporting specifically describes exploitation via a crafted SAMLResponse to a ServiceDesk Plus SAML endpoint. Depending on product, exploitation is possible when SAML single sign-on is enabled or has ever been configured; for some products SAML must still be active. Successful exploitation has been reported as pre-authentication and can result in code execution as NT AUTHORITY\SYSTEM on Windows deployments, or root-level access on the web server in observed incidents.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

The vulnerability enables unauthenticated remote code execution on exposed ManageEngine servers. Because these products often hold privileged identity, authentication, and administrative data, compromise can provide a high-value initial access foothold. Reported post-exploitation outcomes include malware deployment, credential dumping from LSASS, access to stored application credentials, persistence establishment, lateral movement, and broader domain compromise. In incident reporting, actors used exploitation of CVE-2022-47966 to gain root or administrative access, create local admin accounts, deploy remote access tooling and web shells, dump credentials, and pivot deeper into victim environments.

Mitigation

If you can’t patch tonight, do this now.

If immediate patching is not possible, reduce exposure of ManageEngine SAML endpoints and restrict internet access to affected products wherever feasible. Review whether SAML SSO is enabled or was previously configured, because some products remain exploitable if SAML had ever been enabled. Monitor ManageEngine logs for indicators associated with exploitation attempts, including SAML signature validation failures such as 'com.adventnet.authentication.saml.SamlException: Signature validation failed. SAML Response rejected' and related invalid SAML response entries. Hunt for post-exploitation artifacts such as unexpected local admin accounts, web shells, scheduled tasks, remote access tools, and credential-dumping activity. Because exploitation is pre-authentication and broadly scanned, prioritize external attack-surface reduction and rapid patch validation.

Remediation

Patch, then assume compromise.

Apply Zoho/ManageEngine vendor patches for CVE-2022-47966 and upgrade to fixed product versions. The provided content states ManageEngine released patches for affected products by the end of October 2022, and lists fixed-version thresholds including, for example, ServiceDesk Plus 14004 and later, ServiceDesk Plus MSP 13001 and later, Endpoint Central 10.1.2228.11 and later, ADSelfService Plus 6211 and later, Password Manager Pro 12124 and later, and corresponding fixed releases for the other affected products. Follow the vendor advisory for the exact product-specific upgrade path and verify that all internet-facing ManageEngine instances are updated.
PUBLIC EXPLOITS

Exploits

2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).

VALID 2 / 3 TOTALView more in app
CVE-2022-47966MaturityPoCFrameworkhgrab-frameworkVerified exploit

This repository is an exploit for CVE-2022-47966, targeting multiple ManageEngine products vulnerable to unauthenticated remote code execution via SAML SSO. The exploit is implemented in Python (main.py) and is part of the hgrab-framework. It takes a list of target URLs (in a file) and a command to execute as arguments. For each target, it crafts a malicious SAMLResponse XML containing an XSLT transform that leverages Java's Runtime.exec() to execute the supplied command on the server. The payload is sent via HTTP POST to the /SamlResponseServlet endpoint of the target. The exploit is operational, allowing arbitrary command execution if the target is vulnerable. The repository contains a README with usage instructions and a single exploit script (main.py).

SystemVllDisclosed Jan 23, 2023pythonnetwork
CVE-2022-47966MaturityPoCVerified exploit

This repository contains a proof-of-concept (POC) exploit for CVE-2022-47966, a pre-authentication remote code execution vulnerability affecting several ManageEngine products that use Apache Santuario (xmlsec) <= 1.4.1. The exploit is implemented in a single Python script (CVE-2022-47966.py) that crafts a malicious SAML response containing an XSLT transform. This transform abuses Java's Runtime.exec method to execute arbitrary commands on the target server. The script takes three arguments: the target SAML endpoint URL, the command to execute, and an optional SAML issuer. The README.md provides detailed usage instructions, affected product lists, technical analysis links, and example endpoints. The exploit targets network-accessible SAML endpoints and is effective against products that do not perform additional validation on SAML responses. The repository is structured simply, with one exploit script and a comprehensive README.

horizon3aiDisclosed Jan 17, 2023pythonnetwork
EXPOSURE SURFACE

Affected products & vendors

Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.

VendorProductType
ZohocorpManageengine Access Manager Plusapplication
ZohocorpManageengine Ad360application
ZohocorpManageengine Adaudit Plusapplication
ZohocorpManageengine Admanager Plusapplication
ZohocorpManageengine Adselfservice Plusapplication
ZohocorpManageengine Analytics Plusapplication
ZohocorpManageengine Application Control Plusapplication
ZohocorpManageengine Assetexplorerapplication
ZohocorpManageengine Browser Security Plusapplication
ZohocorpManageengine Device Control Plusapplication
ZohocorpManageengine Endpoint Dlp Plusapplication
ZohocorpManageengine Key Manager Plusapplication
ZohocorpManageengine Os Deployerapplication
ZohocorpManageengine Pam360application
ZohocorpManageengine Password Manager Proapplication
ZohocorpManageengine Patch Manager Plusapplication
ZohocorpManageengine Remote Access Plusapplication
ZohocorpManageengine Remote Monitoring And Management Centralapplication
ZohocorpManageengine Servicedesk Plusapplication
ZohocorpManageengine Servicedesk Plus Mspapplication
ZohocorpManageengine Supportcenter Plusapplication
ZohocorpManageengine Vulnerability Manager Plusapplication

Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence5

Every observed campaign linking this CVE to a named adversary.

Associated malware5

Malware families riding this exploit, with evidence and IOCs.

Detection signatures2

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity2

Community discussion across Reddit, Mastodon, and other social sources.