CVE-2018-20753
Kaseya VSA Remote Code Execution Vulnerability
CVSS
9.8
Critical
EPSS
29.3%
p98
KEV
YES
Apr 13, 2022
Exploit Today
79
0-100
Published: Feb 5, 2019 · Last modified: Aug 13, 2026
Product
Kaseya / Virtual System/Server Administrator (VSA)
Vulnerability
Kaseya VSA Remote Code Execution Vulnerability
Added to KEV
Apr 13, 2022
Remediate by
May 4, 2022
Known ransomware use
Yes
Summary description
Kaseya VSA RMM allows unprivileged remote attackers to execute PowerShell payloads on all managed devices.
Required action
Apply updates per vendor instructions.
Notes
https://nvd.nist.gov/vuln/detail/CVE-2018-20753
Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows unprivileged remote attackers to execute PowerShell payloads on all managed devices. In January 2018, attackers actively exploited this vulnerability in the wild.
- blog.huntresslabs.comhttps://blog.huntresslabs.com/deep-dive-kaseya-vsa-mining-payload-c0ac839a0e88
- helpdesk.kaseya.comhttps://helpdesk.kaseya.com/hc/en-gb/articles/360000333152
- blog.huntresslabs.comhttps://blog.huntresslabs.com/deep-dive-kaseya-vsa-mining-payload-c0ac839a0e88
- helpdesk.kaseya.comhttps://helpdesk.kaseya.com/hc/en-gb/articles/360000333152
- www.cisa.govhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-20753