PoC Index

CVE-2018-20753

KEV RANSOMWARECRITICAL 9.8EPSS 29.3%

Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows unprivileged remote attackers to execute PowerShell payloads on all managed devices. In January 2018, attackers actively exploited this vulnerability in the wild.

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
29.34% chance of exploitation in the next 30 days, 98th percentile
CISA KEV
added 2022-04-13, used in ransomware campaigns
Published
2019-02-05
Updated
2026-08-13

Proof-of-concept exploits (1)

References

Related