{"api_version":"1","generated_at":"2026-07-23T08:38:19+00:00","cve":"CVE-2018-20753","urls":{"html":"https://cve.report/CVE-2018-20753","api":"https://cve.report/api/cve/CVE-2018-20753.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2018-20753","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2018-20753"},"summary":{"title":"CVE-2018-20753","description":"Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows unprivileged remote attackers to execute PowerShell payloads on all managed devices. In January 2018, attackers actively exploited this vulnerability in the wild.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2019-02-05 06:29:00","updated_at":"2019-10-03 00:03:00"},"problem_types":["NVD-CWE-noinfo"],"metrics":[],"references":[{"url":"https://helpdesk.kaseya.com/hc/en-gb/articles/360000333152","name":"https://helpdesk.kaseya.com/hc/en-gb/articles/360000333152","refsource":"MISC","tags":["Vendor Advisory"],"title":"Q1 2018 VSA Security Update – Kaseya Support Knowledgebase","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://blog.huntresslabs.com/deep-dive-kaseya-vsa-mining-payload-c0ac839a0e88","name":"https://blog.huntresslabs.com/deep-dive-kaseya-vsa-mining-payload-c0ac839a0e88","refsource":"MISC","tags":["Exploit","Third Party Advisory"],"title":"Deep Dive: Kaseya VSA Mining Payload | by Kyle Hanslovan | Huntress","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2018-20753","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2018-20753","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2018","cve_id":"20753","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"kaseya","cpe5":"virtual_system_administrator","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"20753","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"kaseya","cpe5":"virtual_system_administrator","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":{"cve_year":"2018","cve_id":"20753","cve":"CVE-2018-20753","vendorProject":"Kaseya","product":"Virtual System/Server Administrator (VSA)","vulnerabilityName":"Kaseya VSA Remote Code Execution Vulnerability","dateAdded":"2022-04-13","shortDescription":"Kaseya VSA RMM allows unprivileged remote attackers to execute PowerShell payloads on all managed devices.","requiredAction":"Apply updates per vendor instructions.","dueDate":"2022-05-04","knownRansomwareCampaignUse":"Known","notes":"https://nvd.nist.gov/vuln/detail/CVE-2018-20753","cwes":"","catalogVersion":"2026.07.22","updated_at":"2026-07-22 20:07:15"},"epss":{"cve_year":"2018","cve_id":"20753","cve":"CVE-2018-20753","epss":"0.293360000","percentile":"0.979810000","score_date":"2026-07-22","updated_at":"2026-07-23 00:09:33"},"legacy_qids":[{"cve":"CVE-2018-20753","qid":"731319","title":"Kaseya VSA Remote Code Execution (RCE) Vulnerability"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2018-20753","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows unprivileged remote attackers to execute PowerShell payloads on all managed devices. In January 2018, attackers actively exploited this vulnerability in the wild."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"https://blog.huntresslabs.com/deep-dive-kaseya-vsa-mining-payload-c0ac839a0e88","refsource":"MISC","url":"https://blog.huntresslabs.com/deep-dive-kaseya-vsa-mining-payload-c0ac839a0e88"},{"name":"https://helpdesk.kaseya.com/hc/en-gb/articles/360000333152","refsource":"MISC","url":"https://helpdesk.kaseya.com/hc/en-gb/articles/360000333152"}]}},"nvd":{"publishedDate":"2019-02-05 06:29:00","lastModifiedDate":"2019-10-03 00:03:00","problem_types":["NVD-CWE-noinfo"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":7.5},"severity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:kaseya:virtual_system_administrator:*:*:*:*:*:*:*:*","versionStartIncluding":"9.5","versionEndExcluding":"9.5.0.5","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:kaseya:virtual_system_administrator:*:*:*:*:*:*:*:*","versionStartIncluding":"9.4","versionEndExcluding":"9.4.0.36","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:kaseya:virtual_system_administrator:*:*:*:*:*:*:*:*","versionStartIncluding":"9.3","versionEndExcluding":"9.3.0.35","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2018","CveId":"20753","Ordinal":"145179","Title":"CVE-2018-20753","CVE":"CVE-2018-20753","Year":"2018"},"notes":[{"CveYear":"2018","CveId":"20753","Ordinal":"1","NoteData":"Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows unprivileged remote attackers to execute PowerShell payloads on all managed devices. In January 2018, attackers actively exploited this vulnerability in the wild.","Type":"Description","Title":null},{"CveYear":"2018","CveId":"20753","Ordinal":"2","NoteData":"2019-02-05","Type":"Other","Title":"Published"},{"CveYear":"2018","CveId":"20753","Ordinal":"3","NoteData":"2019-02-05","Type":"Other","Title":"Modified"}]}}}