AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2017-18362

CRITICAL · CVSS 9.8 EPSS 86.71% CISA KEV · Actively Exploited Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2019-02-05 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CISA KEV Details

Status: This CVE is listed in CISA's Known Exploited Vulnerabilities catalog.

Ransomware use: Known

Added to KEV: 2022-05-24

Required action: The impacted product is end-of-life and should be disconnected if still in use.

CVE
CVE-2017-18362
Severity
CRITICAL
CVSS
9.8
EPSS
86.71%

Original NVD Description

ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database. In February 2019, attackers have actively exploited this in the wild to download and execute ransomware payloads on all endpoints managed by the VSA server. If the ManagedIT.asmx page is available via the Kaseya VSA web interface, anyone with access to the page is able to run arbitrary SQL queries, both read and write, without authentication.

Related CVEs

Other vulnerabilities affecting the same vendor(s)