Severity: Low | Attack Vector: Local | Release Date: 09-May-2025
This document highlights the security update for a vulnerability identified in the agent binary dcconfig.exe within Endpoint Central. This issue may allow an attacker to escalate local privileges to SYSTEM.
Chris Au via the ManageEngine Bug Bounty Program
Problem: Privileged file deletion performed by the agent during policy refresh in dcconfig.exe can be exploited to gain SYSTEM-level access.
Fix Builds:
Note: This update is applicable to both On-Premises and Cloud versions.
If you have any questions or require assistance, please contact our support team.