Executive brief
The ConnectWise ManagedITSync integration for Kaseya VSA contains a SQL injection vulnerability in the ManagedIT.asmx page. Unauthenticated remote attackers can execute arbitrary SQL queries to gain full direct access to the Kaseya VSA database, potentially leading to remote command execution. This vulnerability was actively exploited in 2019 to deploy ransomware across managed endpoints.
Affected products
- ConnectWise ManagedITSync integration for Kaseya VSA through 2017
Timeline
- 2019-02-05: disclosed: NVD Published Date
- 2019-02-01: exploited: Attackers actively exploited this in the wild to execute ransomware payloads.
- 2022-05-24: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.