Researchers detailed how CVE-2022-35405, a pre-authentication remote code execution flaw in Zoho/ManageEngine Password Manager Pro, could let an internet-based attacker take over the password vault server through its XML-RPC functionality. The issue was tied to insecure deserialization behavior, aligning with broader OWASP guidance that deserialization flaws can allow untrusted data to trigger arbitrary code execution when applications process attacker-controlled objects.
After gaining code execution on a vulnerable Password Manager Pro instance, red-team researchers showed they could reverse engineer the product’s server-side cryptography and recover sensitive secrets, including the stored database password, the master key, and plaintext managed credentials. Their analysis of the default PostgreSQL deployment found that the server’s ability to decrypt secrets on behalf of users created a single point of failure: once the PMP server was compromised, attackers could extract vaulted credentials and use them to escalate access, potentially reaching Domain Admin in enterprise environments.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Shielder described a red-team assessment in which an internet-exposed ManageEngine Password Manager Pro instance was exploited via CVE-2022-35405, after which the team reverse engineered the product's encryption to recover the database password, master key, and plaintext managed credentials. The write-up concluded that compromise of the PMP server could enable full credential recovery and escalation to Domain Admin.
A reference discusses the Zoho/ManageEngine Password Manager Pro XML-RPC pre-authentication remote code execution vulnerability tracked as CVE-2022-35405. The source was published on 2022-08-01, but the content provided does not explicitly anchor the underlying disclosure event to a specific date.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
shielder.com
Open sourcexz.aliyun.com
Open sourcecheatsheetseries.owasp.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.