DLL Injection Vulnerability in Kaseya Unitrends Backup Appliance
CVE-2021-43037
7.8HIGH
What is CVE-2021-43037?
An issue exists in Kaseya Unitrends Backup Appliance prior to version 10.5.5 that exposes the Windows agent to DLL injection and binary planting vulnerabilities. These issues stem from insecure default permissions, allowing unprivileged users to escalate their privileges to SYSTEM level. This vulnerability can potentially enable attackers to exploit the system, affecting the integrity and confidentiality of the data managed by the backup appliance.