CVE-2018-20753
Summary
| CVE | CVE-2018-20753 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-02-05 06:29:00 UTC |
| Updated | 2019-10-03 00:03:00 UTC |
| Description | Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows unprivileged remote attackers to execute PowerShell payloads on all managed devices. In January 2018, attackers actively exploited this vulnerability in the wild. |
Risk And Classification
EPSS: 0.293360000 probability, percentile 0.979730000 (date 2026-07-21)
CISA KEV: Listed on 2022-04-13; due 2022-05-04; ransomware use Known
Problem Types: NVD-CWE-noinfo
CISA Known Exploited Vulnerability
| Vendor | Kaseya |
|---|---|
| Product | Virtual System/Server Administrator (VSA) |
| Name | Kaseya VSA Remote Code Execution Vulnerability |
| Required Action | Apply updates per vendor instructions. |
| Notes | https://nvd.nist.gov/vuln/detail/CVE-2018-20753 |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Kaseya | Virtual System Administrator | All | All | All | All |
| Application | Kaseya | Virtual System Administrator | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Q1 2018 VSA Security Update – Kaseya Support Knowledgebase | MISC | helpdesk.kaseya.com | Vendor Advisory |
| Deep Dive: Kaseya VSA Mining Payload | by Kyle Hanslovan | Huntress | MISC | blog.huntresslabs.com | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 731319 Kaseya VSA Remote Code Execution (RCE) Vulnerability