Junglewise Threat Intelligence

CVE-2018-20753: Kaseya VSA Remote Code Execution Vulnerability

CVE-2018-20753 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-04-13

Technologies: Kaseya Server Administrator (VSA), Kaseya Virtual System. Vendors: Kaseya.

Executive brief

Kaseya VSA RMM contains a remote code execution vulnerability that allows unprivileged remote attackers to execute PowerShell payloads on all managed devices. The flaw stems from insufficient access control, enabling attackers to bypass authentication and run arbitrary commands.

Affected products

  • Kaseya VSA RMM before 9.3.0.35, 9.4 before 9.4.0.36, and 9.5 before 9.5.0.5

Timeline

  • 2018-01: exploited: Attackers actively exploited this vulnerability in the wild.
  • 2019-02-05: disclosed: NVD Published Date
  • 2022-04-13: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog

Related threats