Critical ManageEngine Flaw Lets Attackers Gain SYSTEM Access Through Windows Login Screen

ManageEngine has fixed a critical remote code execution vulnerability in ADSelfService Plus that could allow an unauthenticated attacker to run code as NT AUTHORITY\SYSTEM through a Windows device’s login screen. The flaw, tracked as CVE-2026-74849, affects the product’s GINA client in builds 7000 and earlier. Organizations should upgrade to build 7001 or later immediately. The […]

This article has been indexed from Cyber Security News

Read the original article: