CVE-2018-20753

CRITICAL(9.8)KEVRansomwareElevated Risk

Kaseya VSA Remote Code Execution Vulnerability

Description

CVE-2018-20753 is an unauthenticated file upload vulnerability in Kaseya VSA, an IT management and remote monitoring platform widely used by managed service providers (MSPs). The vulnerability allows a remote attacker to upload arbitrary files to the server without authentication, ultimately enabling remote code execution. CISA has added CVE-2018-20753 to the Known Exploited Vulnerabilities catalog, and ransomware operators are known to exploit Kaseya VSA vulnerabilities. With an EPSS score of 0.01% (85.2nd percentile), this vulnerability poses a serious supply-chain risk given Kaseya VSA's role as a centralized management platform for thousands of downstream endpoints.

KEV Information

Vendor
Kaseya
Product
Virtual System/Server Administrator (VSA)
Date Added
April 13, 2022
Due Date
May 4, 2022
Required Action
Apply updates per vendor instructions.

CVSS Score

Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HOpen in Calculator
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9

Affected Products

VendorProductVersion
kaseyavirtual system administrator>= 9.3, < 9.3.0.35; >= 9.4, < 9.4.0.36; >= 9.5, < 9.5.0.5

Multiple CVSS Assessments

Source: [email protected](Primary)
9.8
CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0(Secondary)
9.8
CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References

Weakness Type

CWE-434: Unrestricted Upload of File with Dangerous Type

CWE-434 describes a weakness where software allows the upload of files without properly verifying that the file type is safe, enabling an attacker to upload executable code that the server processes or serves in a dangerous way. In CVE-2018-20753, Kaseya VSA accepts file uploads from unauthenticated users without adequate validation of file type or content, allowing an attacker to upload executable files that achieve remote code execution on the server.

Learn more: CWE-434 — Unrestricted Upload of File with Dangerous Type

Impact Analysis

CVE-2018-20753 is particularly dangerous because Kaseya VSA serves as a centralized IT management platform used by MSPs to manage thousands of client endpoints simultaneously. Compromise of the VSA server grants attackers the ability to execute commands, deploy software, and modify configurations across all managed endpoints, creating a devastating supply-chain attack vector. The confidentiality impact extends to all managed organizations' data, credentials, and configurations accessible through the VSA platform. The integrity impact is catastrophic — attackers can push malicious updates, ransomware, or backdoors to all managed endpoints through the trusted VSA management channel. Ransomware operators have been confirmed exploiting Kaseya VSA, demonstrating the real-world severity of this attack path.

Exploit Maturity

CVE-2018-20753 is listed in the CISA Known Exploited Vulnerabilities catalog with confirmed ransomware usage, reflecting the high-value nature of Kaseya VSA as a supply-chain attack vector. While the EPSS score of 0.01% (85.2nd percentile) is moderate compared to some vulnerabilities, the strategic value of compromising an MSP management platform amplifies the real-world impact far beyond what the EPSS score alone suggests. The 2021 Kaseya VSA supply-chain attack demonstrated the devastating potential of exploiting this platform to deploy ransomware to thousands of downstream organizations simultaneously.

Remediation

  1. Apply Kaseya security patches immediately as required by CISA KEV: update Kaseya VSA to the latest version that addresses the unauthenticated file upload vulnerability.
  2. Restrict network access to the Kaseya VSA server to only trusted management networks and authenticated VPN connections, blocking internet-facing access where possible.
  3. Audit the VSA server for unauthorized files, unexpected agent deployments, and signs of post-exploitation activity across all managed endpoints.
  4. Implement network segmentation to isolate the Kaseya VSA management plane from endpoint networks, limiting lateral movement in case of compromise.
  5. Enable multi-factor authentication for all VSA administrative accounts and review audit logs for unauthorized access attempts or configuration changes.

Technical Details

CVE-2018-20753 is an unauthenticated file upload vulnerability in Kaseya VSA that allows a remote attacker to upload arbitrary files to the server without valid credentials. The vulnerability exists because the VSA web application does not properly authenticate requests to certain file upload endpoints and does not adequately validate the type or content of uploaded files. An attacker can upload executable files, such as web shells or malicious scripts, which are then accessible on the server and can be triggered to achieve remote code execution. Given that Kaseya VSA operates as a privileged management agent across all managed endpoints, code execution on the VSA server enables command distribution to the entire managed infrastructure.

Frequently Asked Questions

Is CVE-2018-20753 being actively exploited?

Yes. CVE-2018-20753 is listed in the CISA Known Exploited Vulnerabilities catalog with confirmed ransomware usage. Kaseya VSA has been a high-profile target for supply-chain attacks, most notably the 2021 REvil ransomware campaign.

What products are affected by CVE-2018-20753?

CVE-2018-20753 affects Kaseya VSA, an IT management and remote monitoring platform used by managed service providers to administer client endpoints remotely.

How do I fix CVE-2018-20753?

Update Kaseya VSA to the latest patched version. Restrict internet-facing access to the VSA server, implement multi-factor authentication, and audit for unauthorized files or agent deployments.

How severe is CVE-2018-20753?

CVE-2018-20753 is a critical supply-chain vulnerability. While the EPSS score is moderate, the strategic impact of compromising a Kaseya VSA server is extreme — it enables attackers to deploy malware to thousands of managed endpoints simultaneously through a trusted management channel.

CVSS Score

9.8
CRITICAL(9.8)

EPSS Score

EPSS Score29.34%
EPSS Percentile98.0%

Dates

PublishedFebruary 5, 2019
Last ModifiedAugust 13, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.