peter bassill · operator
$ cve CVE-2018-20753 JSON

CVE-2018-20753 KEV

9.8
CRITICAL · CVSS 3.1 · EPSS 29.3% (pctl 98)

Patch first

On CISA KEV — known exploited in the wild, due 2022-05-04.

Description

Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows unprivileged remote attackers to execute PowerShell payloads on all managed devices. In January 2018, attackers actively exploited this vulnerability in the wild.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS29.34% — more likely to be exploited than 98% of all CVEs
On CISA KEVyes — remediate by 2022-05-04
Public exploitnone known
Published2019-02-05
Last modified2026-08-13

CISA KEV

NameKaseya VSA Remote Code Execution Vulnerability
Added2022-04-13
Due2022-05-04
Vendor / productKaseya / Virtual System/Server Administrator (VSA)
Ransomware useknown

Affected (1)

VendorProduct
kaseyavirtual system administrator

References

→ the Explorer  ·  watch your stack  ·  NVD