CVE-2020-24397: Zohocorp ManageEngine Desktop Central

High severity, CVSS 7.2. EPSS: 15.4% chance of exploitation in the next 30 days.

An issue was discovered in the client side of Zoho ManageEngine Desktop Central 10.0.0.SP-534. An attacker-controlled server can trigger an integer overflow in InternetSendRequestEx and InternetSendRequestByBitrate that leads to a heap-based buffer overflow and Remote Code Execution with SYSTEM privileges.

Affected products

  • Zohocorp ManageEngine Desktop Central: version 10.0.0 only

Published 2020-10-02. Last modified 2026-06-17.