V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2018-20753
CVE
Critical KEVConfirmedExploit available

Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows unprivileged remote attackers to execute PowerShe…

CVSS
9.8
Critical
EPSS
0.30
p97
Published
2018-01-01
Updated
2022-04-13
Description

Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows unprivileged remote attackers to execute PowerShell payloads on all managed devices. In January 2018, attackers actively exploited this vulnerability in the wild.

Tags · CWE
KEVPre-auth
Affected products
Virtual_system_administrator 9.3–9.3.0.35Virtual_system_administrator 9.4–9.4.0.36Virtual_system_administrator 9.5–9.5.0.5
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Timeline
2018-01-01
Published
2022-04-13
Added to KEV
2022-04-13
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.296 · p97
Known exploited (KEV)
Yes
Known exploits — Сканер-ВС
CVE-2018-20753
cisa · https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Enterprise
Affected products
ProductVendorStatus
virtual_system_administrator*Exploited
Source databases
CVE