CVE-2017-12410: Kaseya Virtual System Administrator

High severity, CVSS 7.4. EPSS: 0.2% chance of exploitation in the next 30 days.

It is possible to exploit a Time of Check & Time of Use (TOCTOU) vulnerability by winning a race condition when Kaseya Virtual System Administrator agent 9.3.0.11 and earlier tries to execute its binaries from working and/or temporary folders. Successful exploitation results in the execution of arbitrary programs with "NT AUTHORITY\SYSTEM" privileges.

Affected products

  • Kaseya Virtual System Administrator: up to and including 9.3.0.11

Published 2018-03-26. Last modified 2026-06-17.