CVE-2018-20753: Kaseya VSA Remote Code Execution Vulnerability
Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows unprivileged remote attackers to execute PowerShell payloads on all managed devices. In January 2018, attackers actively exploited this vulnerability in the wild.
Other sources
Kaseya VSA RMM allows unprivileged remote attackers to execute PowerShell payloads on all managed devices.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Kaseya VSA RMMto a version that resolves this vulnerability.Fixed in 9.3.0.35 - Upgrade
Upgrade
Kaseya VSA RMMto a version that resolves this vulnerability.Fixed in 9.4.0.36 - Upgrade
Upgrade
Kaseya VSA RMMto a version that resolves this vulnerability.Fixed in 9.5.0.5 - Compensating control
Isolate managed devices or restrict their network access until the environment is updated to a fixed version to prevent further remote execution of PowerShell payloads.
- Operational
Investigate managed devices for signs of compromise (indicators of executed PowerShell payloads) and remediate any affected systems.
Event History
Frequently Asked Questions
What is the severity of CVE-2018-20753?
CVE-2018-20753 has been assigned a high severity rating due to its potential for remote code execution.
How do I fix CVE-2018-20753?
To mitigate CVE-2018-20753, upgrade Kaseya VSA to a version higher than 9.3.0.35, 9.4.0.36, or 9.5.0.5.
What systems are affected by CVE-2018-20753?
CVE-2018-20753 affects Kaseya VSA versions prior to 9.3.0.35, 9.4.0.36, and 9.5.0.5.
Can CVE-2018-20753 be exploited remotely?
Yes, CVE-2018-20753 allows unprivileged remote attackers to execute PowerShell payloads on all managed devices.
Is there a known exploit for CVE-2018-20753?
Yes, there were active exploits for CVE-2018-20753 reported in the wild in January 2018.