PT-2025-39370 · Zohocorp · Manageengine Endpoint Central

CVE-2025-5494

·

Published

2025-04-24

·

Updated

2025-09-25

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ZohoCorp ManageEngine Endpoint Central versions through 11.4.2500.25 ZohoCorp ManageEngine Endpoint Central versions through 11.4.2508.13
Description An improper privilege management issue exists in the agent setup of ZohoCorp ManageEngine Endpoint Central. The issue relates to how privileges are handled during the agent installation process.
Recommendations Update ZohoCorp ManageEngine Endpoint Central to a version later than 11.4.2500.25. Update ZohoCorp ManageEngine Endpoint Central to a version later than 11.4.2508.13.

Fix

LPE

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-12731
CVE-2025-5494

Affected Products

Manageengine Endpoint Central