← Vulnerability feed

Vulnerability record · CVE-2018-20753 · published 5 February 2019

CVE-2018-20753: Kaseya VSA RMM unauthenticated remote code execution

Kaseya · Virtual System Administrator

Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows unprivileged remote attackers to execute PowerShell payloads on all managed devices. Because VSA is a remote monitoring and management platform, compromise of the server extends execution to every managed endpoint. The record does not specify the exact vulnerable component or root cause (CWE is listed as insufficient information).

9.8 CVSS 3.1 Critical CISA KEV since 13 Apr 2022 Known ransomware use EPSS 29% · top 1.9%
9.8CVSS 3.1 base score, v2 7.5
29%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
5References, 2 tagged exploit
13 Aug 2026Last modified by NVD

Description

Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows unprivileged remote attackers to execute PowerShell payloads on all managed devices. In January 2018, attackers actively exploited this vulnerability in the wild.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable RCE with active in-the-wild exploitation, KEV listing, known ransomware use, and a 98th percentile EPSS score.

What it is

Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows unprivileged remote attackers to execute PowerShell payloads on all managed devices. Because VSA is a remote monitoring and management platform, compromise of the server extends execution to every managed endpoint. The record does not specify the exact vulnerable component or root cause (CWE is listed as insufficient information).

Impact

An attacker gains remote code execution on the VSA server and can push PowerShell payloads to all managed devices, effectively taking control of the managed fleet. CISA KEV notes known ransomware campaign use, so impact can include ransomware deployment across managed endpoints.

Attack surface

Reachable over the network with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Any internet-exposed or reachable VSA instance in the affected version range is a candidate target.

Exploitation

Actively exploited in the wild in January 2018 per the description, and listed in CISA KEV since 2022-04-13 with known ransomware campaign use. EPSS 30-day probability is 0.29336 (98th percentile), and references carry an Exploit tag.

What to do

  • Upgrade Kaseya VSA to R9.3 9.3.0.35, R9.4 9.4.0.36, R9.5 9.5.0.5 or later as directed by the vendor advisory.
  • Remove VSA from direct internet exposure and restrict access to trusted management networks or VPN.
  • Rotate credentials and review VSA administrative and agent accounts for unauthorized changes after any suspected exposure.
  • Apply the vendor's required actions per CISA KEV guidance and verify the installed build actually changed.
  • Monitor managed endpoints for unexpected PowerShell execution pushed from the VSA server.

Detection

  • Hunt for unexpected PowerShell process creation on managed endpoints, especially parented by VSA agent or server processes.
  • Review VSA server logs for anomalous agent commands, script pushes, or authentication from unusual source addresses.
  • Alert on outbound connections from the VSA server to unfamiliar hosts, consistent with payload delivery or mining activity.
  • Audit VSA build versions across the estate to find instances still below the fixed releases.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2018-20753 to the Known Exploited Vulnerabilities catalog on 13 April 2022 as "Kaseya VSA Remote Code Execution Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 4 May 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-20753 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2015-6922Kaseya VSA authentication bypass allows admin account creation and code executionKaseya Virtual System Administrator (VSA) versions 7.x, 8.x, 9.0 and 9.1 before their respective fixed builds fail to properly require authentication…EPSS 82%analysed8.8CVE-2015-6589Kaseya virtual system administrator path traversal vulnerabilityDirectory traversal vulnerability in Kaseya Virtual System Administrator (VSA) 7.0.0.0 before 7.0.0.33, 8..0.0.0 before 8.0.0.23, 9.0.0.0 before 9.0.…EPSS 14%7.5CVE-2019-15506Kaseya virtual system administrator missing authentication for critical function vulnerabilityAn issue was discovered in Kaseya Virtual System Administrator (VSA) through 9.4.0.37. It has a critical information disclosure vulnerability. An una…EPSS 1.8%7.4CVE-2017-12410Kaseya virtual system administrator race condition vulnerabilityIt is possible to exploit a Time of Check & Time of Use (TOCTOU) vulnerability by winning a race condition when Kaseya Virtual System Administrator a…EPSS 0.25%4.3CVE-2015-2863Kaseya virtual system administrator vulnerabilityOpen redirect vulnerability in Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.29, 8.x before 8.0.0.18, 9.0 before 9.0.0.14, and 9.1 befor…EPSS 10%4.0CVE-2015-2862Kaseya virtual system administrator path traversal vulnerabilityDirectory traversal vulnerability in Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.29, 8.x before 8.0.0.18, 9.0 before 9.0.0.14, and 9.1…EPSS 9.5%1.7CVE-2014-2926Kaseya virtual system administrator vulnerabilitykapfa.sys in Kaseya Virtual System Administrator (VSA) 6.5 before 6.5.0.17 and 7.0 before 7.0.0.16 allows local users to cause a denial of service (N…EPSS 0.33%

Source: NIST National Vulnerability Database (record CVE-2018-20753), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.