← Browse

CVE-2018-20753

Act now ● On CISA KEV — actively exploited used in ransomware

Actively exploited — on the CISA KEV list.

CVSS base
9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS — probability of exploitation (30 days)
29.3%
98.1th percentile
CISA KEV
Listed
Added 2022-04-13 · patch by 2022-05-04
Weakness / dates
Published 2019-02-05 · modified 2026-08-13

Description

Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows unprivileged remote attackers to execute PowerShell payloads on all managed devices. In January 2018, attackers actively exploited this vulnerability in the wild.

Affected

kaseya

References

Official: NVD · CVE.org