TL;DR
Zoho Corporation patched a critical ManageEngine ADSelfService Plus vulnerability affecting the GINA client. This flaw allows attackers with physical or remote access to the Windows logon screen to execute arbitrary code. System administrators must update to build 7001 or later to secure their environments.
- CVE: CVE-2026-74849
- CVSS: 9.8 (Critical · CVSSv3)
- Product: Zohocorp ManageEngine ADSelfService Plus
- Affected: < 7001
- Impact: Remote code execution vulnerability
- Status: No confirmed exploitation yet
- Patched in: 7001
- Action: Update to 7001 now
Track every Zoho CVE the moment it's exploited.
Get free email alertsWhy It Matters
Enterprise IT departments deploy ADSelfService Plus to reduce helpdesk tickets by allowing users to reset their own passwords. The GINA client places a self-service portal directly on the Windows lock screen. Therefore, any security flaw in this component exposes the underlying operating system. Because this service runs before a user logs in, it operates with high privileges. A successful exploit grants the attacker NT AUTHORITY\SYSTEM rights. This level of access leads to total host compromise. Fortunately, no exploitation in the wild or public proof-of-concept code has been confirmed.
How The Attack Works
The vulnerability resides within the GINA client’s embedded kiosk browser. This browser renders the password reset interface on the Windows logon screen. According to the security advisory, the flaw involves incorrect error handling. An unauthenticated attacker accesses the embedded browser from the logon screen. By manipulating the browser interface, the attacker bypasses sandbox restrictions. The attacker then forces the underlying application to execute arbitrary commands. Because the GINA client runs as a system service, the commands execute in the SYSTEM context.
Affected Versions
The vulnerability impacts all ManageEngine ADSelfService Plus deployments utilizing the GINA client feature prior to build 7001. Organizations using the standard web portal without deploying the Windows logon screen client are not exposed to this specific attack vector.
Patch Or Mitigation Steps
Administrators must apply the official service pack immediately. Specifically, update your ADSelfService Plus instance to build 7001 or newer. This update corrects the application’s error handling routines. It also applies necessary hardening configurations to the embedded logon-screen browser. Currently, no temporary mitigations or workarounds exist besides removing the GINA client from endpoints.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!