Discover the details of CVE-2021-42955, where Zoho Remote Access Plus Server for Windows Desktop is affected by an unauthorized password reset flaw, allowing non-admin users to reset the Admin account password. Learn about the impact, technical details, and mitigation steps.
Zoho Remote Access Plus Server Windows Desktop binary fixed in version 10.1.2132 is affected by an unauthorized password reset vulnerability that allows non-admin Windows users to reset the Admin account password.
Understanding CVE-2021-42955
This CVE involves an unauthorized password reset vulnerability in Zoho Remote Access Plus Server for Windows Desktop.
What is CVE-2021-42955?
The vulnerability in Zoho Remote Access Plus Server for Windows Desktop allows non-admin Windows users to reset the password of the Admin account due to a flawed password reset mechanism.
The Impact of CVE-2021-42955
The impact is rated as high severity with a CVSS base score of 7.3. The integrity impact is high, and confidentiality impact is none.
Technical Details of CVE-2021-42955
The technical details of this CVE are as follows:
Vulnerability Description
Affected Systems and Versions
Exploitation Mechanism
Mitigation and Prevention
Taking immediate steps and implementing long-term security practices are crucial to mitigate the risks associated with CVE-2021-42955.
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates
Ensure that all systems are regularly updated with the latest patches and security fixes.