An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The privileged vaultServer could be leveraged to create arbitrary writable files, leading to privilege escalation.
References
Link | Resource |
---|---|
https://helpdesk.kaseya.com/hc/en-gb/articles/4412762258961 | Vendor Advisory |
https://www.cyberonesecurity.com/blog/exploiting-kaseya-unitrends-backup-appliance-part-1 | Exploit Third Party Advisory |
https://www.cyberonesecurity.com/blog/exploiting-kaseya-unitrends-backup-appliance-part-2 | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2021-12-06 04:15
Updated : 2024-02-28 18:48
NVD link : CVE-2021-43040
Mitre link : CVE-2021-43040
CVE.ORG link : CVE-2021-43040
JSON object : View
Products Affected
kaseya
- unitrends_backup
CWE