---
id: CVE-2018-20753
title: >-
  Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before
  9.5.0.5 allows unprivileged remote attackers to execute PowerShell payloads on
  all managed devices
summary: >-
  Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before
  9.5.0.5 allows unprivileged remote attackers to execute PowerShell payloads on
  all managed devices. In January 2018, attackers actively exploited this
  vulnerabili…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
vendor: kaseya
product: virtual_system_administrator
affected:
  - 'virtual_system_administrator >= 9.3, < 9.3.0.35'
  - 'virtual_system_administrator >= 9.4, < 9.4.0.36'
  - 'virtual_system_administrator >= 9.5, < 9.5.0.5'
patched:
  - virtual_system_administrator 9.5.0.5
published: '2019-02-05'
updated: '2026-08-13'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2018-20753'
references:
  - url: >-
      https://blog.huntresslabs.com/deep-dive-kaseya-vsa-mining-payload-c0ac839a0e88
    label: cve@mitre.org
  - url: 'https://helpdesk.kaseya.com/hc/en-gb/articles/360000333152'
    label: cve@mitre.org
  - url: >-
      https://blog.huntresslabs.com/deep-dive-kaseya-vsa-mining-payload-c0ac839a0e88
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://helpdesk.kaseya.com/hc/en-gb/articles/360000333152'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-20753
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - kev
  - in-the-wild
epss: 0.29336
epssPercentile: 0.98138
kev: true
kevDateAdded: '2022-04-13'
kevDueDate: '2022-05-04'
kevRansomware: true
exploited: true
ingestedAt: '2026-08-13T06:00:54.844Z'
---

## Overview

Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows unprivileged remote attackers to execute PowerShell payloads on all managed devices. In January 2018, attackers actively exploited this vulnerability in the wild.

## Affected

- `virtual_system_administrator >= 9.3, < 9.3.0.35`
- `virtual_system_administrator >= 9.4, < 9.4.0.36`
- `virtual_system_administrator >= 9.5, < 9.5.0.5`

## Remediation

Upgrade past the affected range:

- `virtual_system_administrator 9.5.0.5`
