Zohocorp ManageEngine ADManager Plus versions before 8025 are vulnerable to NTLM Hash Exposure.  This vulnerability is exploitable only by technicians who have the “Impersonate as Admin” option enabled.
History

Mon, 15 Dec 2025 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 15 Dec 2025 11:15:00 +0000

Type Values Removed Values Added
Description Zohocorp ManageEngine ADManager Plus versions before 8025 are vulnerable to NTLM Hash Exposure.  This vulnerability is exploitable only by technicians who have the “Impersonate as Admin” option enabled.
Title NTLM Hash Exposure Vulnerability
First Time appeared Zohocorp
Zohocorp manageengine Admanager Plus
Weaknesses CWE-200
CPEs cpe:2.3:a:zohocorp:manageengine_admanager_plus:*:*:*:*:*:*:*:*
Vendors & Products Zohocorp
Zohocorp manageengine Admanager Plus
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Zohocorp

Published:

Updated: 2025-12-15T13:11:14.660Z

Reserved: 2025-10-13T04:36:28.773Z

Link: CVE-2025-11670

cve-icon Vulnrichment

Updated: 2025-12-15T13:11:09.639Z

cve-icon NVD

Status : Received

Published: 2025-12-15T11:15:38.607

Modified: 2025-12-15T11:15:38.607

Link: CVE-2025-11670

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.