Attackers exploited CVE-2019-8394 in Zoho ManageEngine ServiceDesk Plus to upload web shells and compromise networks despite a patch released in early 2019, according to SOC Prime’s December 2020 report. The vulnerability affects versions before 10.0 build 10012 and involves insufficient sanitization of user-supplied input in crafted SMTP requests. Exploitation requires authentication but can be performed with minimal privileges, including guest credentials, enabling arbitrary system command execution.
Web shells can give attackers persistent access to affected servers and support further network compromise. Organizations running vulnerable builds should upgrade to a patched version and investigate exposed systems for unauthorized web shells; patching alone does not remove an existing compromise. SOC Prime also pointed defenders to NSA and Australian Signals Directorate guidance on detecting and preventing web shell malware, providing complementary measures for identifying malicious server-side files and reducing opportunities for persistent access.

See which actors are running it and whether you're in range.
3 events from the most recent confirmed update back to the earliest known activity.
CVE-2019-8394 was disclosed on February 18, 2019, affecting versions before 10.0 build 10012. Insufficient sanitization of crafted SMTP requests allows an authenticated attacker with minimal permissions to upload web shells and execute arbitrary system commands.
Zoho released a patch for CVE-2019-8394 in Q1 2019. ServiceDesk Plus version 10.0 build 10012 or later addresses the vulnerability.
Threat actors began exploiting CVE-2019-8394 immediately after its disclosure, using the vulnerability to upload web shells. These shells can provide persistent access and facilitate further network compromise.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.