PT-2019-13724 · Kaseya · Kaseya Vsa Rmm
Published
2019-10-11
·
Updated
2021-07-21
·
CVE-2019-14510
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Kaseya VSA RMM versions through 9.5.0.22
Description
An issue in the default configuration of the LAN Cache feature creates a local account
FSAdminxxxxxxxxx on the server and clients assigned to the LAN Cache, adding it to the local Administrators group. On Domain Controllers, this account is created as a domain account and added to the domain BUILTINAdministrators group. An attacker can use Pass-the-Hash techniques with the FSAdminxxxxxxxxx hash from any LAN Cache client to gain administrative rights on any Domain Controller.Recommendations
For versions through 9.5.0.22, consider disabling the LAN Cache feature to prevent the creation of the
FSAdminxxxxxxxxx account until a patch is available. Restrict access to the local Administrators group and the domain BUILTINAdministrators group to minimize the risk of exploitation. Avoid using the default configuration of the LAN Cache feature until the issue is resolved.Exploit
Fix
Incorrect Default Permissions
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Kaseya Vsa Rmm