CVE-2024-24409 | Privilege Escalation

Exp

Zohocorp ManageEngine ADManager Plus versions 7203 and prior are vulnerable to Privilege Escalation in the Modify Computers option.

Published: 2024-11-08 Last update: 2024-11-13 Assigner: 0fc0942c-577d-436f-ae8e-945763c79b02 Source: 0fc0942c-577d-436f-ae8e-945763c79b02

Conclusion & alert: CVE-2024-24409 is rated High Exploit Risk (80/100): CVSS High severity, with high exploitation likelihood (EPSS 6.24%, 91th percentile). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Public exploit references (Exploit-DB) for CVE-2024-24409

EDB-ID Source Kind Published Link
52148 exploit_db edb 2025-04-09 Exploit-DB ↗

Exploit prediction scoring system (EPSS) score for CVE-2024-24409

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-05-18 8.30% 6.24% -2.06%
2 2026-05-07 5.23% 8.30% +3.07%
3 2026-04-26 5.23%

Full EPSS history (27 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2024-24409

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
8.8 3.1 HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Click to expand
Attack vector (AV:N)
Could be attacked over the internet or any normal routed network—not just someone sitting at the machine.
Attack complexity (AC:L)
Once they can reach the bug, pulling it off is straightforward—no weird race conditions or rare setup.
Privileges required (PR:L)
A normal user session is enough; they don’t have to be admin.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:U)
Damage stays in the same “trust bubble” as the broken component—no big spill into unrelated systems.
Confidentiality (C:H)
Serious risk that confidential data gets exposed in a big way.
Integrity (I:H)
They could widely tamper with or forge data—trust in the data is badly hurt.
Availability (A:H)
Could take the service down hard or make it unusable for people who depend on it.
2.8 5.9 0fc0942c-577d-436f-ae8e-945763c79b02
8.8 3.1 HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Click to expand
Attack vector (AV:N)
Could be attacked over the internet or any normal routed network—not just someone sitting at the machine.
Attack complexity (AC:L)
Once they can reach the bug, pulling it off is straightforward—no weird race conditions or rare setup.
Privileges required (PR:L)
A normal user session is enough; they don’t have to be admin.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:U)
Damage stays in the same “trust bubble” as the broken component—no big spill into unrelated systems.
Confidentiality (C:H)
Serious risk that confidential data gets exposed in a big way.
Integrity (I:H)
They could widely tamper with or forge data—trust in the data is badly hurt.
Availability (A:H)
Could take the service down hard or make it unusable for people who depend on it.
2.8 5.9 [email protected]

Weakness enumeration for CVE-2024-24409

Affected software / configurations for CVE-2024-24409

Vendor Product Version Raw CPE
zohocorp manageengine_admanager_plus 6.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:6.1:-:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 6.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:6.1:6100:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 6.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:6.1:6101:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 6.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:6.1:6102:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 6.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:6.1:6103:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 6.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:6.1:6104:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 6.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:6.1:6105:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 6.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:6.1:6106:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 6.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:6.1:6107:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 6.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:6.1:6108:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 6.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:6.1:6109:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 6.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:6.1:6110:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 6.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:6.1:6111:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 6.2 cpe:2.3:a:zohocorp:manageengine_admanager_plus:6.2:*:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 6.5.7 cpe:2.3:a:zohocorp:manageengine_admanager_plus:6.5.7:*:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 6.6 cpe:2.3:a:zohocorp:manageengine_admanager_plus:6.6:6657:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 6.6 cpe:2.3:a:zohocorp:manageengine_admanager_plus:6.6:6660:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 6.6.5 cpe:2.3:a:zohocorp:manageengine_admanager_plus:6.6.5:*:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.0 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.0:-:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.0 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.0:7000:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.0 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.0:7010:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.0 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.0:7011:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.0 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.0:7020:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.0 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.0:7030:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.0 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.0:7040:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.0 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.0:7041:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.0 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.0:7050:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.0 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.0:7051:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.0 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.0:7052:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.0 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.0:7053:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.0 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.0:7054:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.0 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.0:7055:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.0 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.0:7056:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.0 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.0:7060:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.0 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.0:7061:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.0 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.0:7062:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.0 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.0:7063:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.0 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.0:7064:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.0 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.0:7065:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.0 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.0:7066:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.1:-:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.1:7100:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.1:7101:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.1:7102:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.1:7110:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.1:7111:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.1:7112:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.1:7113:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.1:7114:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.1:7115:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.1:7116:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.1:7117:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.1:7118:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.1:7120:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.1:7121:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.1:7122:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.1:7123:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.1:7124:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.1:7125:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.1:7126:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.1:7130:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.1:7131:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.1:7140:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.1:7141:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.1:7150:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.1:7151:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.1:7160:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.1:7161:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.1:7162:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.1:7163:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.1:7170:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.1:7171:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.1:7180:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.1:7181:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.1:7182:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.1:7183:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.1:7184:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.1:7185:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.1:7186:*:*:*:*:*:*
zohocorp manageengine_admanager_plus 7.1 cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.1:7188:*:*:*:*:*:*

References for CVE-2024-24409

cvelogic Threat Intelligence