ManageEngine has addressed a high-severity remote code execution vulnerability in ADSelfService Plus, which could permit an unauthenticated attacker with physical access to execute arbitrary code as NT AUTHORITY\SYSTEM This article explores execution vulnerability adselfservice. . This flaw is tracked as CVE-2026-74849, affecting the product's GINA client component, which integrates ADSelfService Plus password reset and account-unlock functionalities into the Windows login experience.

This level of access could enable an attacker to fully compromise an affected device, including creating privileged accounts, modifying security controls, installing persistence mechanisms, extracting locally accessible secrets, or deploying malware before a legitimate user logs in.

Although the issue is not described as remotely exploitable over a network, physical access remains a meaningful threat in shared workspaces, branch offices, kiosks, reception areas, data-center environments, classrooms, and other locations where endpoints may be accessible to unauthorized individuals. Organizations should also consider scenarios involving an attacker who already has limited physical presence inside a facility, including malicious insiders, visitors, contractors, or adversaries who obtain temporary access to an unlocked office or endpoint. Endpoint monitoring teams should also investigate unexpected SYSTEM-level processes, newly created local administrator accounts, changes to authentication components, and unusual activity preceding user logon.

Join 16,000+ SOC teams by utilizing ANY.RUN to enhance threat investigations and minimize manual workload.