Loading
It is possible to exploit a Time of Check & Time of Use (TOCTOU) vulnerability by winning a race condition when Kaseya Virtual System Administrator agent 9.3.0.11 and earlier tries to execute its binaries from working and/or temporary folders. Successful exploitation results in the execution of arbitrary programs with "NT AUTHORITY\SYSTEM" privileges.
Use CWE-362, Kaseya vendor hub and Virtual System Administrator product page to widen CVE-2017-12410 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2018-20753, CVE-2015-6922 and CVE-2015-6589 for nearby disclosures in the same product family.