Local Account Vulnerability in Kaseya VSA Remote Monitoring and Management Solution
CVE-2019-14510
What is CVE-2019-14510?
A vulnerability in Kaseya VSA allows for the creation of a local administrative account (FSAdminxxxxxxxxx) on servers hosting the LAN Cache feature. By default, this account gains local Administrator group privileges on all connected clients. If one of these clients operates as a Domain Controller, the same account is inadvertently created as a domain account, granting it membership in the domain's BUILTIN\Administrators group. This misconfiguration enables attackers to exploit Pass-the-Hash techniques, allowing them to pass the hash of the FSAdmin account from any LAN Cache client to the Domain Controller, thus compromising administrative access across the domain.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
