Back
CVE-2018-20753
CRITICAL
CISA KEV
Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows unprivileged remote attackers to execute PowerShell payloads on all managed devices. In January 2018, attackers actively exploited this vulnerability in the wild.
Published: Feb 5, 2019
Modified: Aug 13, 2026
NVD-CWE-noinfo
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products (3)
| Vendor | Product | Version |
|---|---|---|
| kaseya | virtual_system_administrator | * ≥ 9.3 < 9.3.0.35 |
| kaseya | virtual_system_administrator | * ≥ 9.4 < 9.4.0.36 |
| kaseya | virtual_system_administrator | * ≥ 9.5 < 9.5.0.5 |
GitHub Security Advisory GHSA-hhg2-f289-m44w
Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows...
References (5)
- https://blog.huntresslabs.com/deep-dive-kaseya-vsa-mining-payload-c0ac839a0e88 Exploit, Third Party Advisory
- https://helpdesk.kaseya.com/hc/en-gb/articles/360000333152 Vendor Advisory
- https://blog.huntresslabs.com/deep-dive-kaseya-vsa-mining-payload-c0ac839a0e88 Exploit, Third Party Advisory
- https://helpdesk.kaseya.com/hc/en-gb/articles/360000333152 Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-20753 US Government Resource
Risk Scores
CVSS Score
9.8 / 10
EPSS Score
29.34%
Top 2% most likely to be exploited
Threat Score
78 / 100
CISA Known Exploited
Date Added:
2022-04-13
Due Date:
2022-05-04
Required Action:
Apply updates per vendor instructions.
Used in Ransomware Campaigns
Data Sources
NVD
CISA KEV
EPSS
GitHub