CVE-2025-14601 PUBLISHED

vsDesk Task Scheduler OS Command Injection

Assigner: Kaspersky
Reserved: 12.12.2025 Published: 20.08.2026 Updated: 20.08.2026

An OS command injection vulnerability in vsDesk allows an authenticated attacker with administrative privileges to execute arbitrary operating system commands due to insufficient input filtering. An attacker can exploit this flaw to disrupt web server operations, expose sensitive data, or potentially achieve full server compromise.

Apply patch from vendor https://vsdesk.ru/ . Versions 14.0101 and on have the patch.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.6

Product Status

Vendor vsDesk
Product vsDesk
Versions Default: unaffected
  • Version 11.06.02 is affected
  • Version 14.0101 is unaffected

Credits

  • The vulnerability was discovered by Kirill Nikolaev from Kaspersky (https://kaspersky.com) finder

References

Problem Types

  • CWE-676: Use of Potentially Dangerous Function CWE

Impacts

  • CAPEC-210 : Abuse Existing Functionality