CVE-2021-43037

HIGH

Kaseya Unitrends <10.5.5 - Privilege Escalation

Title source: llm
STIX 2.1

Description

An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The Unitrends Windows agent was vulnerable to DLL injection and binary planting due to insecure default permissions. This allowed privilege escalation from an unprivileged user to SYSTEM.

Scores

CVSS v3 7.8
EPSS 0.0050
EPSS Percentile 39.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-427
Status published
Products (1)
kaseya/unitrends_backup 10.0 - 10.5.5
Published Dec 06, 2021
Tracked Since Feb 18, 2026