QID 731319
Date Published: 2024-04-11
QID 731319: Kaseya VSA Remote Code Execution (RCE) Vulnerability
CVE-2018-20753 is a critical vulnerability residing within Kaseya VSA RMM, a software application facilitating remote monitoring and management. This vulnerability grants unauthenticated remote attackers the ability to execute PowerShell payloads on all devices managed by the Kaseya VSA RMM system.
Affected Versions:
Kaseya R9.5 prior to Patch 9.5.0.5
Kaseya R9.4 prior to Patch 9.4.0.36
Kaseya R9.3 prior to Patch 9.3.0.35
Patched Versions:
Kaseya R9.5: Patch 9.5.0.5
Kaseya R9.4: Patch 9.4.0.36
Kaseya R9.3: Patch 9.3.0.35
QID Detection Logic (Unauthenticated):
This QID checks for vulnerable versions of Kaseya VSA by sending an HTTP GET request to the 'vsapres/web20/core/login.aspx' endpoint and extracting the version from the response received.
Successful exploitation of the vulnerability may allow unauthenticated attackers to remotely execute malicious code on all managed devices. This translates to potential data theft, malware deployment, operational disruption, and even ransomware attacks, making it a critical vulnerability.
- Kaseya Security Advisory -
helpdesk.kaseya.com/hc/en-gb/articles/360000333152-Q1-2018-VSA-Security-Update
CVEs related to QID 731319
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Kaseya Security Advisory |
|