---
id: CVE-2025-14600
title: >-
  An insecure deserialization vulnerability in vsDesk allows a remote attacker
  to gain unauthorized administrative access
summary: >-
  An insecure deserialization vulnerability in vsDesk allows a remote attacker
  to gain unauthorized administrative access. By manipulating application
  configuration data, an attacker can force the system to authenticate against
  an arbitrar…
severity: none
cwe:
  - CWE-305
published: '2026-08-19'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T10:10:00.263'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-14600'
references:
  - url: >-
      https://github.com/klsecservices/Advisories/blob/master/KLSA-00296-Admin-Account-Takeover-via-Path-Traversal-in-vsDesk.md
    label: vulnerability@kaspersky.com
  - url: 'https://vsdesk.ru/news/vyshla-novaya-versiya-140422'
    label: vulnerability@kaspersky.com
tags:
  - nvd
ingestedAt: '2026-09-29T10:31:36.299Z'
---

## Overview

An insecure deserialization vulnerability in vsDesk allows a remote attacker to gain unauthorized administrative access. By manipulating application configuration data, an attacker can force the system to authenticate against an arbitrary LDAP server and provision a new administrative account.




Apply patch from vendor  https://vsdesk.ru/ . Versions 14.0402 and on have the patch.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
