Zoho Desk — Vulnerability Disclosure
Atumcell-discovered weakness in Zoho's Desk help-desk product, disclosed to the vendor and reported alongside the MoveIt Transfer finding.
Affected
Zoho (Zoho Desk)
Severity
High
Published
1 January 2024
Summary
Atumcell research surfaced a security weakness in Zoho's Desk product — a widely deployed help-desk and customer-support platform. Disclosure was coordinated with Zoho, and the finding was covered in the trade press alongside the related MoveIt Transfer disclosure.
Detail
Help-desk and customer-support platforms increasingly sit in the same operational tier as identity and email infrastructure: they hold customer-confidential records, internal-process metadata, and frequently inherited authentication paths to other systems. Zoho Desk is widely deployed in mid-market and SMB segments where assurance investment lags the product's effective access scope.
[TODO(matthew): Replace this paragraph with the specific finding — the affected component, the failure mode, the conditions required for exploitation, and the data categories at risk. Add the CVE ID to the metadata above if one was assigned.]
The finding was disclosed to Zoho through their coordinated disclosure process. Channel Futures reported the disclosure in December 2024. The pattern this finding reinforces — assurance work that stops at the boundary of "core IT" and treats SaaS support tooling as out-of-scope — is one of the more common gaps surfaced in mid-market technical due diligence.
References
Need this kind of research for your organisation?
Atumcell runs targeted vulnerability research, OT/ICS assessments and adversary simulation for organisations where the consequences of compromise are categorically different from IT.
Or read about full advisory engagements.
Strategic consultation
Discuss a research scope
$500 · 30 minutes
More on these topics
Other research
Disclosure
Progress MoveIt Transfer — Vulnerability Disclosure
Atumcell-discovered weakness in Progress Software's MoveIt Transfer file-transfer product, coordinated with the vendor and publicly disclosed.
Research
N-able Workgroup Guideline — Security Risk to MSPs
Research finding that N-able's published workgroup guideline created a meaningful exposure for managed service providers and their downstream clients.
Research
Physically Hacking SCADA — Cyber-Physical Attack Chains
Research on cyber-physical attack chains against SCADA systems, demonstrating how digital compromises produce physical-layer effects.