Authenticated PowerShell Injection in DNS Query Resolution Policy leads to RCE
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.2epss 3.6%
exploitation probability
3.6%top 11% of all CVEs
observed exploitation
nono source reports it
ManageEngine DDI Central versions below 6201 are vulnerable to Command injection in Windows DNS Query Resolution Policy name field leading to remote code execution.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected products
Zohocorp · DDI Central