CVE-2025-14600
vsDesk
An insecure deserialization vulnerability in vsDesk allows a remote attacker to gain unauthorized administrative access. By manipulating application configuration data, an attacker can force the system to authenticate against an arbitrary LDAP server and provision a new administrative account. Apply patch from vendor https://vsdesk.ru/ . Versions 14.0402 and on have the patch.
- CVSS
- 9.3
- EPSS
- 0.37% 30.4% percentile
- CISA KEV
- Not listed
- Published
- 2026.08.20