CVE-2017-18362criticalunder attackransomwareCWE-89

CVE-2017-18362

Published · Updated

100Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 9.8epss 87%
from disclosure to weapon2382 days
Published on NVDFeb 5
1st PoC+2382d
CISA KEV+1204d
exploitation probability
87%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
1 public exploit(s)
Action required by CISAfederal deadline: 2022-06-14

The impacted product is end-of-life and should be disconnected if still in use.

In short

The ConnectWise ManagedITSync integration in Kaseya VSA allowed attackers to run any SQL command directly on the database without logging in, giving them complete control over the system and all computers managed by it.

Technical detail

An unauthenticated SQL injection vulnerability in the ManagedIT.asmx endpoint (CWE-89) permits direct database access via arbitrary SQL queries without authentication. Remote attackers can read and write database contents, enabling full system compromise and lateral movement to all managed endpoints. This was actively exploited in February 2019 for ransomware deployment.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database. In February 2019, attackers have actively exploited this in the wild to download and execute ransomware payloads on all endpoints managed by the VSA server. If the ManagedIT.asmx page is available via the Kaseya VSA web interface, anyone with access to the page is able to run arbitrary SQL queries, both read and write, without authentication.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.