CVE-2017-18362
KEV ransomware PoC largeUnauthenticated SQL Injection in Kaseya VSA ConnectWise ManagedITSync Integration
CISA: Kaseya VSA SQL Injection Vulnerability
An unauthenticated SQL injection (CWE-89) exists in the ConnectWise ManagedITSync integration (through 2017) for Kaseya Virtual System Administrator (VSA), triggered through the ManagedIT.asmx page of the VSA web interface. Any unauthenticated attacker who can reach that page over the network can submit arbitrary SQL queries, both read and write, gaining full direct access to the VSA database and effectively running remote commands on the server. Because VSA servers centrally manage endpoints for managed service providers, compromise can cascade downstream: in February 2019 attackers actively exploited this flaw to download and execute ransomware payloads on all endpoints managed by affected VSA servers. Organizations are affected if they run Kaseya VSA with the ManagedITSync integration enabled and the ManagedIT.asmx page reachable by untrusted users. Exploitation is confirmed in the wild (CISA KEV, added 2022-05-24; known ransomware use), EPSS estimates an 86.8% probability of exploitation within 30 days, and CISA notes the impacted product is end-of-life.
What to do: Because CISA notes the impacted product is end-of-life, disconnect or decommission any Kaseya VSA still running the ConnectWise ManagedITSync integration; otherwise update the integration beyond the 2017 version or disable it and remove public network access to the ManagedIT.asmx page of the VSA web interface. Restrict the VSA web interface to trusted networks and check managed endpoints for signs of the February 2019 ransomware exploitation.
| ConnectWise ManagedITSync integration for Kaseya VSA | through 2017 |
| Kaseya Virtual System Administrator (VSA) | installations running the ConnectWise ManagedITSync integration (through 2017) with the ManagedIT.asmx page exposed via the VSA web interface |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database. In February 2019, attackers have actively exploited this in the wild to download and execute ransomware payloads on all endpoints managed by the VSA server. If the ManagedIT.asmx page is available via the Kaseya VSA web interface, anyone with access to the page is able to run arbitrary SQL queries, both read and write, without authentication.
- Affected
- Kaseya Virtual System/Server Administrator (VSA)
- Required action
- The impacted product is end-of-life and should be disconnected if still in use.
- Due date
- Ransomware use
- Known
- Vendors
- connectwise
- Products
- manageditsync
- Weakness
- CWE-89
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H