DLL Injection Vulnerability in Kaseya Unitrends Backup Appliance
CVE-2021-43037

7.8HIGH

Key Information:

Vendor

Kaseya

Vendor
CVE Published:
6 December 2021

What is CVE-2021-43037?

An issue exists in Kaseya Unitrends Backup Appliance prior to version 10.5.5 that exposes the Windows agent to DLL injection and binary planting vulnerabilities. These issues stem from insecure default permissions, allowing unprivileged users to escalate their privileges to SYSTEM level. This vulnerability can potentially enable attackers to exploit the system, affecting the integrity and confidentiality of the data managed by the backup appliance.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.