April 13, 2022 · Applied Cybernetics Group
CVE-2018-20753 — Kaseya Virtual System/Server Administrator (VSA)
known ransomware use
Kaseya VSA Remote Code Execution Vulnerability
- Added to KEV
2022-04-13- Federal due date
2022-05-04- Vendor
- Kaseya
- Product
- Virtual System/Server Administrator (VSA)
- EPSS
- 98.1th percentile (score 0.293, as of
2026-09-16) - NVD CVSS v3.1
- 9.8 (CRITICAL)
- Ransomware use
- Known
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2018-20753
CISA short description
Kaseya VSA RMM allows unprivileged remote attackers to execute PowerShell payloads on all managed devices.
Required action
Apply updates per vendor instructions.
NVD description
Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows unprivileged remote attackers to execute PowerShell payloads on all managed devices. In January 2018, attackers actively exploited this vulnerability in the wild.