PT-2019-13724 · Kaseya · Kaseya Vsa Rmm

Published

2019-10-11

·

Updated

2021-07-21

·

CVE-2019-14510

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Kaseya VSA RMM versions through 9.5.0.22
Description An issue in the default configuration of the LAN Cache feature creates a local account FSAdminxxxxxxxxx on the server and clients assigned to the LAN Cache, adding it to the local Administrators group. On Domain Controllers, this account is created as a domain account and added to the domain BUILTINAdministrators group. An attacker can use Pass-the-Hash techniques with the FSAdminxxxxxxxxx hash from any LAN Cache client to gain administrative rights on any Domain Controller.
Recommendations For versions through 9.5.0.22, consider disabling the LAN Cache feature to prevent the creation of the FSAdminxxxxxxxxx account until a patch is available. Restrict access to the local Administrators group and the domain BUILTINAdministrators group to minimize the risk of exploitation. Avoid using the default configuration of the LAN Cache feature until the issue is resolved.

Exploit

Fix

Incorrect Default Permissions

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-14510

Affected Products

Kaseya Vsa Rmm