CVE-2020-10189: Deserialization Vulnerability in Zoho ManageEngine Desktop Central 10 Patched (SRC-2020-0011)
by Satnam Narang on March 6, 2020
Zoho releases a patch for a critical remote code execution flaw in ManageEngine one day after the vulnerability was publicly disclosed.
Update 03/09/2020: Updated the Analysis section to include information on reports of active exploitation of this vulnerability.