vendor:
Kaseya VSA agent
by:
NF
N/A
CVSS
HIGH
Privilege Escalation
CWE
Product Name: Kaseya VSA agent
Affected Version From: <= 9.5
Affected Version To: <= 9.5
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 10
2019
Kaseya VSA agent <= 9.5 privilege escalation
This exploit allows a low privileged group to gain excessive permissions to a folder used by an elevated process in Kaseya VSA agent <= 9.5. By appending malicious code to a script file dropped in the default working directory, an attacker can execute arbitrary commands as SYSTEM.
Mitigation:
Update to a version higher than 9.5 to fix this vulnerability. Remove unnecessary permissions from the default working folder.