CVE-2018-20753
KEV ransomware PoC massUnauthenticated RCE in Kaseya VSA RMM
CISA: Kaseya VSA Remote Code Execution Vulnerability
Kaseya VSA (Virtual System/Server Administrator), a remote monitoring and management platform used heavily by managed service providers, contains a remote code execution flaw that allows unprivileged remote attackers to execute attacker-supplied PowerShell payloads. An attacker who can reach a VSA server over the network can trigger execution without privileged access, and because VSA orchestrates agents on enrolled machines, the payload can run on all devices that server manages. Successful exploitation therefore yields code execution on the RMM server itself and potentially across an entire downstream managed estate, making it a high-value foothold for ransomware. Any organization running the affected product is exposed - most commonly MSPs and internal IT departments - along with every client device managed by a compromised VSA instance. CISA added the flaw to the KEV catalog on 2022-04-13 with known ransomware use; no public proof-of-concept is known.
What to do: Apply updates per Kaseya's instructions as required by the CISA KEV listing, upgrading VSA to the latest patched release rather than relying on partial mitigations, since this platform has a history of critical flaws. Restrict direct internet exposure of VSA servers (firewall/VPN only) and hunt on managed endpoints for unexpected PowerShell execution or newly created agent procedures, given the known ransomware use.
| Kaseya Virtual System/Server Administrator (VSA) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows unprivileged remote attackers to execute PowerShell payloads on all managed devices. In January 2018, attackers actively exploited this vulnerability in the wild.
- Affected
- Kaseya Virtual System/Server Administrator (VSA)
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- kaseya
- Products
- virtual system administrator
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.