CVE-2015-6922
60Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 82%
from disclosure to weapon0 days
Published on NVDFeb 17
1st PoCSep 29
metasploitSep 23
exploitation probability
82%top 1% of all CVEs
observed exploitation
nono source reports it
4 public exploit(s)
Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.33, 8.x before 8.0.0.23, 9.0 before 9.0.0.19, and 9.1 before 9.1.0.9 does not properly require authentication, which allows remote attackers to bypass authentication and (1) add an administrative account via crafted request to LocalAuth/setAccount.aspx or (2) write to and execute arbitrary files via a full pathname in the PathData parameter to ConfigTab/uploader.aspx.
Affected products
n/a · n/apublic PoCs found — 4✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/38401exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/38351cve_referencepacketstormsecurity.com/files/133782/Kaseya-Virtual-System-Administrator-Code-Execution-Privilege-Escalation.htmlunverifiedcve_referencewww.exploit-db.com/exploits/38351/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://packetstormsecurity.com/files/133782/Kaseya-Virtual-System-Administrator-Code-Execution-Privilege-Escalation.htmlhttps://helpdesk.kaseya.com/entries/96164487--Kaseya-Security-Advisoryhttps://www.exploit-db.com/exploits/38351/http://www.zerodayinitiative.com/advisories/ZDI-15-448http://www.zerodayinitiative.com/advisories/ZDI-15-449