A phishing email harvests staff credentials. CVE-2023-23397 on an unpatched Windows endpoint enables lateral movement to the Domain Controller, giving the attacker administrative access to all district systems including FERPA-protected student records.
A third-party vendor has VPN access with unrestricted LAN privileges. Combined with CVE-2023-46604 on the SIS server, an attacker with vendor credentials can reach the PowerSchool database directly — the exact pattern from the December 2024 breach affecting 60M+ student records.
sis-server-01.lusd.local is internet-facing with CVE-2023-46604 unpatched — a remote code execution vulnerability with CVSS 9.8. An external attacker can exploit this to deploy ransomware across the district network with no credential theft required.
The Meraki firewall allows unrestricted traffic from the student VLAN (10.10.0.0/16) to the server VLAN (10.20.0.0/16) on port 445. A compromised student Chromebook — or a student probing the network — can reach file servers and the SIS server directly.
Upload one CSV from Defender, Google Admin, or Tenable. Your first attack path appears in under 10 minutes.