CVE-2015-6922 is a critical vulnerability in Kaseya Virtual System Administrator (VSA) versions 7.x before 7.0.0.33, 8.x before 8.0.0.23, 9.0 before 9.0.0.19, and 9.1 before 9.1.0.9. The vulnerability arises from improper authentication checks, allowing remote attackers to bypass authentication and (1) add a Master Administrator account via a crafted request to LocalAuth/setAccount.aspx, or (2) upload and execute arbitrary files via directory traversal in the PathData parameter to ConfigTab/uploader.aspx. This enables unauthenticated attackers to gain full administrative control and execute arbitrary code on the VSA server and all managed endpoints.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a single Metasploit module (modules/exploits/windows/http/kaseya_uploader.rb) that exploits an arbitrary file upload vulnerability (CVE-2015-6922) in Kaseya VSA versions 7 through 9.1. The exploit targets the 'uploader.aspx' endpoint, allowing an unauthenticated attacker to upload a malicious ASP file to various potential directories on the server. Once uploaded, the ASP file (containing a Metasploit-generated payload) is executed, resulting in remote code execution with IUSR privileges. The module is weaponized, supporting customizable payloads and automatic cleanup. The code is written in Ruby and leverages Metasploit's HttpClient, EXE, and FileDropper mixins. The exploit is network-based, requiring access to the Kaseya VSA web interface, and attempts uploads to several common installation paths to maximize success. The repository is structured as a typical Metasploit exploit module, with all logic contained in a single file.
This repository contains a single Metasploit auxiliary module (modules/auxiliary/admin/http/kaseya_master_admin.rb) that exploits a vulnerability in Kaseya VSA (CVE-2015-6922) versions 7 through 9.1. The module abuses the /LocalAuth/setAccount.aspx endpoint, which is intended to be accessible only from localhost but lacks proper access controls. By sending crafted HTTP GET and POST requests, the module retrieves a session value and then submits attacker-supplied credentials to create a new Master Administrator account on the target Kaseya VSA instance. The exploit requires the attacker to specify the target URI and the desired credentials for the new account. Upon success, the module reports the creation of the new account and stores the credentials in the Metasploit credential database. The code is written in Ruby and is designed to be run within the Metasploit Framework.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.