Local Account Vulnerability in Kaseya VSA Remote Monitoring and Management Solution
CVE-2019-14510

6.7MEDIUM

Key Information:

Vendor

Kaseya

Status
Vendor
CVE Published:
11 October 2019

What is CVE-2019-14510?

A vulnerability in Kaseya VSA allows for the creation of a local administrative account (FSAdminxxxxxxxxx) on servers hosting the LAN Cache feature. By default, this account gains local Administrator group privileges on all connected clients. If one of these clients operates as a Domain Controller, the same account is inadvertently created as a domain account, granting it membership in the domain's BUILTIN\Administrators group. This misconfiguration enables attackers to exploit Pass-the-Hash techniques, allowing them to pass the hash of the FSAdmin account from any LAN Cache client to the Domain Controller, thus compromising administrative access across the domain.

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.