CVE-2018-20753 is a critical vulnerability affecting Kaseya VSA RMM versions before R9.3 9.3.0.35, R9.4 9.4.0.36, and R9.5 9.5.0.5. This flaw allows unprivileged remote attackers to execute PowerShell payloads on all managed devices, posing a severe risk to organizations utilizing the affected software. With a CVSS score of 9.8 (Critical), it has a low attack complexity and requires no user interaction, leading to potential complete compromise of confidentiality, integrity, and availability. This vulnerability has been actively exploited in the wild since January 2018, is listed in CISA's KEV catalog, and has a high EPSS score, indicating a significant likelihood of exploitation. Despite no public Metasploit or ExploitDB modules, it garners substantial community discussion and media coverage, highlighting its critical nature and ongoing threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 9.3, < 9.3.0.35CPE matchmatch criteria | cpe:2.3:a:kaseya:virtual_system_administrator:*:*:*:*:*:*:*:* | ||
>= 9.4, < 9.4.0.36CPE matchmatch criteria | cpe:2.3:a:kaseya:virtual_system_administrator:*:*:*:*:*:*:*:* | ||
>= 9.5, < 9.5.0.5CPE matchmatch criteria | cpe:2.3:a:kaseya:virtual_system_administrator:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.