Impact
The vulnerability arises from insecure deserialization in vsDesk, allowing a remote attacker to manipulate application configuration data. By exploiting this flaw, an attacker can force the system to authenticate against an arbitrary LDAP server and provision a new administrative account, granting full administrative privileges without legitimate credentials. This results in a complete compromise of the application’s security, enabling unrestricted control, data modification, and potentially further lateral movement within the infrastructure.
Affected Systems
vsDesk applications deployed before the vendor’s patch release are affected. The vendor announced a patch beginning with version 14.0402, which addresses the insecure deserialization flaw. All prior builds lacking this update are vulnerable.
Risk and Exploitability
The CVSS score of 9.3 classifies this vulnerability as critical, indicating a high likelihood of successful exploitation under suitable conditions. EPSS data is not available, implying no current exploitation statistics, but the flaw’s severity and the straightforward attacker path—remote configuration manipulation—specifically target the authentication mechanism. It is not listed in CISA’s KEV catalog, but the potential for unrestricted admin access warrants high vigilance. The most probable attack vector is remote network access to the application’s configuration interface, where crafted data can be injected to trigger the LDAP authentication bypass.
OpenCVE Enrichment