Direct Inward Dialing: +1 408 916 9393
| Vulnerability Details | |
| Severity | Medium |
| CVE ID | CVE-2025-11670 |
| Affected software versions | Build 8022 and older |
| Fixed version | Build 8025 |
| Fixed on | Oct 13, 2025 |
The CVE-2025-11670 refers to a security vulnerability where the NTLM hash of the service account configured in ADManager Plus was exposed to the authorized technicians. This issue has been fixed in build 8025, and the release notes can be found here.
This vulnerability could allow technicians with permissions to NTFS Management and the 'Impersonate as Admin' option enabled to retrieve the NTLM hash of a service account.
Update your ADManager Plus instance to its latest build by installing the service pack.
This vulnerability was reported by bitxer via Zoho's Bug Bounty program.
Select a language to translate the contents of this web page:
Fill this form, and we'll contact you rightaway.
Our technical support team will get in touch with you at the earliest."