
ADManager Plus Build < 7230 Elevation of Privilege
A technician user with the 'Modify user general properties' role and logon access to the server where ADManager is installed.
If the technician user has logon rights on the server , they can escalate privileges to the service account or the user account that runs the Admanager with high privileges. The user can create an arbitrary directory through the web application and then copy a DLL file into this directory. When ADManager is restarted, the DLL file is executed with the privileges of the user running ADManager.
Profile Attributes.....\\jre\\lib\\ext\\amd64 value to homeDirectory parameter and forward request.amd64 will be created under the C:\Program Files\ManageEngine\ADManager Plus\jre\lib\ext directory. The technician user has Full control over the amd64 directory.sunmscapi.dll or sunec.dll (this DLL could cause the ADManager Plus application to fail to start) DLL file to obtain reverse shell.C:\Program Files\ManageEngine\ADManager Plus\jre\lib\ext\amd64. Under normal conditions, the user can not copy files under the C:\Program Files\ManageEngine\ADManager Plus\jre\lib\ext\ directory due to insufficient privilege. However, the user obtains write right under the “amd64” directory exploiting arbitrary directory creating vulnerability and can copy these files.