First published: Mon Dec 06 2021(Updated: )
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The Unitrends Windows agent was vulnerable to DLL injection and binary planting due to insecure default permissions. This allowed privilege escalation from an unprivileged user to SYSTEM.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Kaseya Unitrends Backup Software | >=10.0<10.5.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-43037 is considered a high-severity vulnerability due to its potential for privilege escalation.
To fix CVE-2021-43037, update the Kaseya Unitrends Backup Appliance to version 10.5.5 or later.
CVE-2021-43037 affects users of Kaseya Unitrends Backup versions prior to 10.5.5.
CVE-2021-43037 is a DLL injection and binary planting vulnerability that allows for privilege escalation.
Yes, CVE-2021-43037 could potentially be exploited by unprivileged users to gain SYSTEM privileges.