Greetings and New Year Wishes from ManageEngine.
This security update resolves a vulnerability in Desktop Central which allows creation of users by remote code execution. An attacker who exploits this vulnerability could gain access to the Desktop Central web console for performing remote desktop management activities. For more details on this vulnerability, refer to
here
This vulnerability has been fixed in Desktop Central #build 90109. The current EXE available in the website includes this fix. Existing customers can download and install this security update to fix this vulnerability