This vulnerability is exploitable only by technicians who have the “Impersonate as Admin” option enabled.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 18 Dec 2025 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:zohocorp:manageengine_admanager_plus:8.0:8000:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_admanager_plus:8.0:8001:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_admanager_plus:8.0:8002:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_admanager_plus:8.0:8010:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_admanager_plus:8.0:8011:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_admanager_plus:8.0:8012:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_admanager_plus:8.0:8020:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_admanager_plus:8.0:8021:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_admanager_plus:8.0:8022:*:*:*:*:*:* |
Mon, 15 Dec 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 15 Dec 2025 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Zohocorp ManageEngine ADManager Plus versions before 8025 are vulnerable to NTLM Hash Exposure. This vulnerability is exploitable only by technicians who have the “Impersonate as Admin” option enabled. | |
| Title | NTLM Hash Exposure Vulnerability | |
| First Time appeared |
Zohocorp
Zohocorp manageengine Admanager Plus |
|
| Weaknesses | CWE-200 | |
| CPEs | cpe:2.3:a:zohocorp:manageengine_admanager_plus:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Zohocorp
Zohocorp manageengine Admanager Plus |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Zohocorp
Published:
Updated: 2025-12-15T13:11:14.660Z
Reserved: 2025-10-13T04:36:28.773Z
Link: CVE-2025-11670
Updated: 2025-12-15T13:11:09.639Z
Status : Analyzed
Published: 2025-12-15T11:15:38.607
Modified: 2025-12-18T01:51:54.977
Link: CVE-2025-11670
No data.
OpenCVE Enrichment
No data.