ZeroHour

CVE-2018-20753

KEV ransomware PoC mass

Unauthenticated RCE in Kaseya VSA RMM

CISA: Kaseya VSA Remote Code Execution Vulnerability

CVSS 3.1
9.8 critical
EPSS
29%p98
Published
()
KEV added
AI analysis

Kaseya VSA (Virtual System/Server Administrator), a remote monitoring and management platform used heavily by managed service providers, contains a remote code execution flaw that allows unprivileged remote attackers to execute attacker-supplied PowerShell payloads. An attacker who can reach a VSA server over the network can trigger execution without privileged access, and because VSA orchestrates agents on enrolled machines, the payload can run on all devices that server manages. Successful exploitation therefore yields code execution on the RMM server itself and potentially across an entire downstream managed estate, making it a high-value foothold for ransomware. Any organization running the affected product is exposed - most commonly MSPs and internal IT departments - along with every client device managed by a compromised VSA instance. CISA added the flaw to the KEV catalog on 2022-04-13 with known ransomware use; no public proof-of-concept is known.

What to do: Apply updates per Kaseya's instructions as required by the CISA KEV listing, upgrading VSA to the latest patched release rather than relying on partial mitigations, since this platform has a history of critical flaws. Restrict direct internet exposure of VSA servers (firewall/VPN only) and hunt on managed endpoints for unexpected PowerShell execution or newly created agent procedures, given the known ransomware use.

Affected
Kaseya Virtual System/Server Administrator (VSA)
Estimated exposure
mass≈35,000–40,000 VSA customer deployments managing millions of downstream endpoints, though only a few thousand VSA servers are directly exposed to the internet — Public reporting around the July 2021 Kaseya VSA ransomware incident put the VSA install base at roughly 35,000–40,000 customer deployments, each managing many downstream devices, while public internet scans showed only a few thousand VSA…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows unprivileged remote attackers to execute PowerShell payloads on all managed devices. In January 2018, attackers actively exploited this vulnerability in the wild.

CISA Known Exploited Vulnerability
Affected
Kaseya Virtual System/Server Administrator (VSA)
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
kaseya
Products
virtual system administrator
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.