Junglewise Threat Intelligence

CVE-2017-18362: Kaseya VSA SQL Injection Vulnerability

CVE-2017-18362 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-05-24

Technologies: Kaseya Server Administrator (VSA), Kaseya Virtual System. Vendors: Kaseya, ConnectWise.

Executive brief

The ConnectWise ManagedITSync integration for Kaseya VSA contains a SQL injection vulnerability in the ManagedIT.asmx page. Unauthenticated remote attackers can execute arbitrary SQL queries to gain full direct access to the Kaseya VSA database, potentially leading to remote command execution. This vulnerability was actively exploited in 2019 to deploy ransomware across managed endpoints.

Affected products

  • ConnectWise ManagedITSync integration for Kaseya VSA through 2017

Timeline

  • 2019-02-05: disclosed: NVD Published Date
  • 2019-02-01: exploited: Attackers actively exploited this in the wild to execute ransomware payloads.
  • 2022-05-24: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.

Related threats