CVE-2018-20753
Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows unprivileged remote attackers to execute PowerShell payloads on all managed devices. In January 2018, attackers actively exploited this vulnerability in the wild.
Published:Feb 5, 2019
Last Modified:Nov 7, 2025
EPS:Feb 5, 2019
EPSS Score:0.3865
CVSS Score:9.8
CISA Notification
Description
Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows unprivileged remote attackers to execute PowerShell payloads on all managed devices. In January 2018, attackers actively exploited this vulnerability in the wild.
Required Action:
Apply updates per vendor instructions.
Notes:
No extra notes provided.
Due Date
May 4, 2022
1591 days ago
Alert Date
Apr 13, 2022
1612 days ago
Affected Products
Vendor
Product
Action
Vendor
Kaseya
Product
Virtual System Administrator
Kaseya
Virtual System Administrator
Exploits
Common Weakness Enumeration
No CWE recorded yet
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
