Privilege Escalation Vulnerability During JAR Extraction
This document addresses the privilege escalation vulnerability in the Endpoint Central agent during JAR file extraction.
Severity: Medium
Attack Vector: Local
Fixed build: For versions 11.5.2600.18 or below, upgrade to version 11.5.2600.19. For versions 11.4.2540.22 or below, upgrade to version 11.4.2540.23.
Fix release date: 2026-02-16
Reported by: Sandro Poppi via the ZohoCorp Bug Bounty Program
What was the problem?
During a patch scan, the Endpoint Central agent extracted JAR files in a directory controlled by a standard user. This could be exploited by a local user to elevate privileges to SYSTEM. We have addressed the issue to prevent unauthorized privilege escalation.
How to fix it?
Upgrading to the latest version is strongly advised due to the severity of this vulnerability. To upgrade, follow the steps below:
- Log in to the Endpoint Central console and click your current build number in the top-right corner.
- You will be able to find the latest build applicable to your installation.
- Download the PPM and complete the upgrade.
For any further questions or concerns regarding this issue, write a mail to our at support team.