{"api_version":"1","generated_at":"2026-07-24T17:33:54+00:00","cve":"CVE-2021-43037","urls":{"html":"https://cve.report/CVE-2021-43037","api":"https://cve.report/api/cve/CVE-2021-43037.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-43037","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-43037"},"summary":{"title":"CVE-2021-43037","description":"An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The Unitrends Windows agent was vulnerable to DLL injection and binary planting due to insecure default permissions. This allowed privilege escalation from an unprivileged user to SYSTEM.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2021-12-06 04:15:00","updated_at":"2022-11-28 21:40:00"},"problem_types":["CWE-427"],"metrics":[],"references":[{"url":"https://www.cyberonesecurity.com/blog/exploiting-kaseya-unitrends-backup-appliance-part-1","name":"https://www.cyberonesecurity.com/blog/exploiting-kaseya-unitrends-backup-appliance-part-1","refsource":"MISC","tags":[],"title":"Exploiting Kaseya Unitrends Backup Appliance – Part 1 - CyberOne Security","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://helpdesk.kaseya.com/hc/en-gb/articles/4412762258961","name":"https://helpdesk.kaseya.com/hc/en-gb/articles/4412762258961","refsource":"MISC","tags":[],"title":"Security check","mime":"text/html","httpstatus":"403","archivestatus":"404"},{"url":"https://www.cyberonesecurity.com/blog/exploiting-kaseya-unitrends-backup-appliance-part-2","name":"https://www.cyberonesecurity.com/blog/exploiting-kaseya-unitrends-backup-appliance-part-2","refsource":"MISC","tags":[],"title":"Exploiting Kaseya Unitrends Backup Appliance – Part 2 - CyberOne Security","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-43037","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-43037","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"43037","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"kaseya","cpe5":"unitrends_backup","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2021-43037","qid":"376380","title":"Kaseya Unitrends Backup Appliance Multiple Vulnerabilities (4412762258961)"},{"cve":"CVE-2021-43037","qid":"730324","title":"Kaseya Unitrends Backup Appliance Multiple Vulnerabilities (4412762258961)"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2021-43037","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The Unitrends Windows agent was vulnerable to DLL injection and binary planting due to insecure default permissions. This allowed privilege escalation from an unprivileged user to SYSTEM."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"refsource":"MISC","name":"https://helpdesk.kaseya.com/hc/en-gb/articles/4412762258961","url":"https://helpdesk.kaseya.com/hc/en-gb/articles/4412762258961"},{"refsource":"MISC","name":"https://www.cyberonesecurity.com/blog/exploiting-kaseya-unitrends-backup-appliance-part-1","url":"https://www.cyberonesecurity.com/blog/exploiting-kaseya-unitrends-backup-appliance-part-1"},{"refsource":"MISC","name":"https://www.cyberonesecurity.com/blog/exploiting-kaseya-unitrends-backup-appliance-part-2","url":"https://www.cyberonesecurity.com/blog/exploiting-kaseya-unitrends-backup-appliance-part-2"}]}},"nvd":{"publishedDate":"2021-12-06 04:15:00","lastModifiedDate":"2022-11-28 21:40:00","problem_types":["CWE-427"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:M/Au:N/C:C/I:C/A:C","accessVector":"LOCAL","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE","baseScore":6.9},"severity":"MEDIUM","exploitabilityScore":3.4,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:kaseya:unitrends_backup:*:*:*:*:*:*:*:*","versionStartIncluding":"10.0","versionEndExcluding":"10.5.5","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"43037","Ordinal":"219559","Title":"CVE-2021-43037","CVE":"CVE-2021-43037","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"43037","Ordinal":"1","NoteData":"** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.","Type":"Description","Title":null}]}}}