EXPOSURES › CVE-2018-20753
CVE-2018-20753
CRITICAL ⌖ ON CISA KEV · EXPLOITEDThe Kaseya VSA vulnerability allowed attackers to remotely execute PowerShell on managed devices, leading to ransomware infections across numerous organizations.
A critical remote code execution vulnerability in Kaseya VSA allowed unauthenticated attackers to execute arbitrary PowerShell code on managed endpoints, which was actively exploited in a ransomware attack. DIB organizations using Kaseya VSA must immediately patch and review their security posture to prevent similar compromises; this failure highlights the risk of supply chain vulnerabilities and inadequate security controls.
Shame score — The widespread ransomware infection resulting from this easily exploitable vulnerability demonstrates a significant failure in Kaseya's security practices and has severe reputational consequences.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Kaseya VSA RMM allows unprivileged remote attackers to execute PowerShell payloads on all managed devices.