PT-2026-78540 · Vsdesk · Vsdesk
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
vsDesk versions prior to 14.0402
Description
An insecure deserialization issue allows a remote attacker to obtain unauthorized administrative access. By manipulating application configuration data, an attacker can force the system to authenticate against an arbitrary LDAP server and provision a new administrative account. Insecure deserialization occurs when untrusted data is used to abuse the logic of an application to execute arbitrary code or manipulate system behavior.
Recommendations
Update to version 14.0402 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vsdesk