CVE-2018-20753
critical · 9.8Actively exploitedOn the CISA Known Exploited Vulnerabilities catalog
Apply updates per vendor instructions.
Added 2022-04-13Remediation due 2022-05-04
Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows unprivileged remote attackers to execute PowerShell payloads on all managed devices. In January 2018, attackers actively exploited this vulnerability in the wild.
9.8
CVSS
29.3%
EPSS (exploit prob.)
98th
EPSS percentile
2019-02-05
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| kaseya | virtual_system_administrator | >= 9.3, < 9.3.0.35 |
| kaseya | virtual_system_administrator | >= 9.4, < 9.4.0.36 |
| kaseya | virtual_system_administrator | >= 9.5, < 9.5.0.5 |
Check a specific version with /api/v1/cve/match.
References
- https://blog.huntresslabs.com/deep-dive-kaseya-vsa-mining-payload-c0ac839a0e88
- https://helpdesk.kaseya.com/hc/en-gb/articles/360000333152
- https://blog.huntresslabs.com/deep-dive-kaseya-vsa-mining-payload-c0ac839a0e88
- https://helpdesk.kaseya.com/hc/en-gb/articles/360000333152
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-20753
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2018-20753