Critical ManageEngine Flaw Lets Attackers Gain SYSTEM Access Through Windows Login Screen

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


ManageEngine has fixed a critical remote code execution vulnerability in ADSelfService Plus that could allow an unauthenticated attacker to run code as NT AUTHORITYSYSTEM through a Windows device’s login screen.

The flaw, tracked as CVE-2026-74849, affects the product’s GINA client in builds 7000 and earlier. Organizations should upgrade to build 7001 or later immediately.

The issue resides in the GINA client, a component that places ADSelfService Plus password-reset and account-unlock functions directly on the Windows logon screen.

It presents these functions in an embedded kiosk-style browser before a user signs in, allowing employees to reset passwords or unlock accounts without reaching the Windows desktop.

Critical ManageEngine Flaw

According to ManageEngine’s advisory, an attacker with access to the Windows login screen could abuse the embedded browser to execute arbitrary code in the SYSTEM security context. SYSTEM is one of the most privileged local accounts on Windows.

Code running under this context can modify protected files, create or alter user accounts, install services, turn off security tooling, access sensitive local data, and establish persistent control over the endpoint.

The vulnerability is classified as a remote code execution issue in the GINA client. Public vulnerability records identify the underlying weakness as CWE-78, Improper Neutralization of Special Elements used in an OS Command, commonly known as OS command injection.

The ManageEngine-assigned CVSS v3.1 score is 9.8 out of 10, rated Critical, with a network attack vector, low attack complexity, no privileges required, and no user interaction required.

Although the vendor advisory describes exploitation as requiring access to the Windows logon screen, defenders should treat affected systems as high risk. Login-screen software operates before normal user authentication and may run with elevated permissions.

A successful compromise could give an attacker complete control of a workstation or server hosting the vulnerable GINA component.

CVE-2026-74849 affects ManageEngine ADSelfService Plus builds 7000 and below. ManageEngine resolved the issue in build 7001, released on August 24, 2026. The update corrects the application’s error handling and hardens the embedded browser exposed at the Windows login screen.

Security teams should identify all endpoints using the ADSelfService Plus GINA client and confirm the installed product build. Any instance below build 7001 should be updated through ManageEngine’s ADSelfService Plus service pack process.

Administrators should also review endpoint logs for unexpected processes, suspicious command execution, newly created services, changes to local administrator accounts, and unusual activity originating around logon-screen use.

Where an immediate update is not possible, organizations should limit physical and remote access to affected Windows login screens, restrict exposure of the GINA-related service to untrusted networks, and closely monitor the affected hosts. These measures reduce exposure but do not replace the vendor update.

Marouane Belabbassi and Amjad E Alhejaili reported the vulnerability through the Zoho BugBounty program. With a working pathway to SYSTEM-level code execution on vulnerable systems, patching remains the most important remediation step.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

The post Critical ManageEngine Flaw Lets Attackers Gain SYSTEM Access Through Windows Login Screen appeared first on Cyber Security News.