Vulnerability record · CVE-2018-20753 · published 5 February 2019
CVE-2018-20753: Kaseya VSA RMM unauthenticated remote code execution
Kaseya · Virtual System Administrator
Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows unprivileged remote attackers to execute PowerShell payloads on all managed devices. Because VSA is a remote monitoring and management platform, compromise of the server extends execution to every managed endpoint. The record does not specify the exact vulnerable component or root cause (CWE is listed as insufficient information).
Description
Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows unprivileged remote attackers to execute PowerShell payloads on all managed devices. In January 2018, attackers actively exploited this vulnerability in the wild.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable RCE with active in-the-wild exploitation, KEV listing, known ransomware use, and a 98th percentile EPSS score.
What it is
Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows unprivileged remote attackers to execute PowerShell payloads on all managed devices. Because VSA is a remote monitoring and management platform, compromise of the server extends execution to every managed endpoint. The record does not specify the exact vulnerable component or root cause (CWE is listed as insufficient information).
Impact
An attacker gains remote code execution on the VSA server and can push PowerShell payloads to all managed devices, effectively taking control of the managed fleet. CISA KEV notes known ransomware campaign use, so impact can include ransomware deployment across managed endpoints.
Attack surface
Reachable over the network with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Any internet-exposed or reachable VSA instance in the affected version range is a candidate target.
Exploitation
Actively exploited in the wild in January 2018 per the description, and listed in CISA KEV since 2022-04-13 with known ransomware campaign use. EPSS 30-day probability is 0.29336 (98th percentile), and references carry an Exploit tag.
What to do
- Upgrade Kaseya VSA to R9.3 9.3.0.35, R9.4 9.4.0.36, R9.5 9.5.0.5 or later as directed by the vendor advisory.
- Remove VSA from direct internet exposure and restrict access to trusted management networks or VPN.
- Rotate credentials and review VSA administrative and agent accounts for unauthorized changes after any suspected exposure.
- Apply the vendor's required actions per CISA KEV guidance and verify the installed build actually changed.
- Monitor managed endpoints for unexpected PowerShell execution pushed from the VSA server.
Detection
- Hunt for unexpected PowerShell process creation on managed endpoints, especially parented by VSA agent or server processes.
- Review VSA server logs for anomalous agent commands, script pushes, or authentication from unusual source addresses.
- Alert on outbound connections from the VSA server to unfamiliar hosts, consistent with payload delivery or mining activity.
- Audit VSA build versions across the estate to find instances still below the fixed releases.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2018-20753 to the Known Exploited Vulnerabilities catalog on 13 April 2022 as "Kaseya VSA Remote Code Execution Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 4 May 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://blog.huntresslabs.com/deep-dive-kaseya-vsa-mining-payload-c0ac839a0e88 | ExploitThird Party Advisory |
| https://helpdesk.kaseya.com/hc/en-gb/articles/360000333152 | Vendor Advisory |
| https://blog.huntresslabs.com/deep-dive-kaseya-vsa-mining-payload-c0ac839a0e88 | ExploitThird Party Advisory |
| https://helpdesk.kaseya.com/hc/en-gb/articles/360000333152 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-20753 | US Government Resource |
Track CVE-2018-20753 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-20753), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.