ZeroHour

CVE-2017-18362

KEV ransomware PoC large

Unauthenticated SQL Injection in Kaseya VSA ConnectWise ManagedITSync Integration

CISA: Kaseya VSA SQL Injection Vulnerability

CVSS 3.1
9.8 critical
EPSS
87%p100
Published
()
KEV added
AI analysis

An unauthenticated SQL injection (CWE-89) exists in the ConnectWise ManagedITSync integration (through 2017) for Kaseya Virtual System Administrator (VSA), triggered through the ManagedIT.asmx page of the VSA web interface. Any unauthenticated attacker who can reach that page over the network can submit arbitrary SQL queries, both read and write, gaining full direct access to the VSA database and effectively running remote commands on the server. Because VSA servers centrally manage endpoints for managed service providers, compromise can cascade downstream: in February 2019 attackers actively exploited this flaw to download and execute ransomware payloads on all endpoints managed by affected VSA servers. Organizations are affected if they run Kaseya VSA with the ManagedITSync integration enabled and the ManagedIT.asmx page reachable by untrusted users. Exploitation is confirmed in the wild (CISA KEV, added 2022-05-24; known ransomware use), EPSS estimates an 86.8% probability of exploitation within 30 days, and CISA notes the impacted product is end-of-life.

What to do: Because CISA notes the impacted product is end-of-life, disconnect or decommission any Kaseya VSA still running the ConnectWise ManagedITSync integration; otherwise update the integration beyond the 2017 version or disable it and remove public network access to the ManagedIT.asmx page of the VSA web interface. Restrict the VSA web interface to trusted networks and check managed endpoints for signs of the February 2019 ransomware exploitation.

Affected
ConnectWise ManagedITSync integration for Kaseya VSAthrough 2017
Kaseya Virtual System Administrator (VSA)installations running the ConnectWise ManagedITSync integration (through 2017) with the ManagedIT.asmx page exposed via the VSA web interface
Estimated exposure
largeroughly 10,000-100,000 exposed Kaseya VSA server installations with the integration enabled (MSP deployments), each managing hundreds to thousands of… — No install counts or public scan figures are provided in the data, so this order-of-magnitude estimate reflects Kaseya VSA's deployment pattern as a widely used MSP remote-management platform whose typically internet-exposed servers each…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database. In February 2019, attackers have actively exploited this in the wild to download and execute ransomware payloads on all endpoints managed by the VSA server. If the ManagedIT.asmx page is available via the Kaseya VSA web interface, anyone with access to the page is able to run arbitrary SQL queries, both read and write, without authentication.

CISA Known Exploited Vulnerability
Affected
Kaseya Virtual System/Server Administrator (VSA)
Required action
The impacted product is end-of-life and should be disconnected if still in use.
Due date
Ransomware use
Known
Vendors
connectwise
Products
manageditsync
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news