What Is Kaseya VSA?
Kaseya VSA (Virtual System/Server Administrator) is a remote monitoring and management (RMM) platform used by managed service providers (MSPs) to manage client endpoints at scale. VSA agents are deployed on thousands of client machines per MSP customer, enabling centralized patch management, script execution, remote control, and monitoring. Because VSA has privileged agent access to all managed endpoints, a compromise of a Kaseya VSA server gives an attacker access to deploy code or ransomware across every managed client simultaneously — making MSP RMM platforms the highest-leverage target in the threat landscape.
Overview
CVE-2017-18362 is a critical SQL injection vulnerability in the ConnectWise ManagedITSync integration plugin for Kaseya VSA. The plugin exposes unauthenticated remote commands that allow direct, unrestricted access to the Kaseya VSA database — enabling an attacker to read all MSP and client data, extract credentials, modify configurations, and ultimately deploy malicious scripts to all managed endpoints. The affected product is end-of-life; CISA requires disconnecting it. Ransomware operators have exploited Kaseya VSA to deploy ransomware across MSP client networks simultaneously.
Affected Versions
ConnectWise ManagedITSync integration plugin for Kaseya VSA — versions before the November 2018 patched release. Organizations still running end-of-life Kaseya VSA with this plugin are at maximum risk and should immediately disconnect the system.
Technical Details
Root Cause: Unauthenticated SQL Injection in ManagedITSync Integration
CVE-2017-18362 is an SQL injection vulnerability (CWE-89) in the ConnectWise ManagedITSync plugin — a third-party integration that synchronizes data between Kaseya VSA and ConnectWise Manage (a PSA/ticketing platform used by MSPs). The plugin exposes HTTP endpoints that accept parameters passed directly into database queries without sanitization or authentication checks. An attacker can send crafted requests to these endpoints to:
- Execute arbitrary SQL queries against the Kaseya VSA database
- Read all VSA configuration data, agent credentials, and managed client information
- Extract administrator credentials and session tokens
- Modify VSA database records to create backdoor administrator accounts
- Trigger VSA to deploy malicious scripts/packages to all managed endpoints
MSP supply chain amplification: The devastating aspect of VSA compromise is the blast radius — a single Kaseya VSA server typically manages hundreds to thousands of endpoints across dozens of client organizations. Code deployed via VSA installs with system/root privileges on every managed machine simultaneously.
Attack Characteristics
| Attribute | Detail |
|---|---|
| Attack Vector | Network — unauthenticated HTTP |
| Authentication | None required |
| Impact | Full database read/write access, script execution on all agents |
| Blast Radius | All MSP client endpoints managed by the VSA instance |
Discovery
Discovered and reported to ConnectWise; patched in November 2018. The CVE was published in February 2019, over a year after the patch.
Exploitation Context
- MSP ransomware supply chain attacks: Ransomware operators specifically target MSP management platforms because compromising a single VSA server enables simultaneous ransomware deployment across all client organizations; this is more efficient than attacking individual targets
- REvil/Sodinokibi MSP campaigns: The REvil ransomware group conducted multiple campaigns specifically targeting Kaseya VSA and similar RMM platforms; while the high-profile July 2021 Kaseya VSA attack used CVE-2021-30116, earlier REvil MSP campaigns exploited older VSA vulnerabilities including CVE-2017-18362 on unpatched instances
- End-of-life status: The affected Kaseya VSA product has reached end-of-life; CISA's required action is disconnection rather than patching, reflecting that no further security updates are available
- CISA KEV (2022): Added May 24, 2022 reflecting continued exploitation of MSP infrastructure by ransomware operators
Remediation
-
Disconnect end-of-life Kaseya VSA immediately — if still running the affected EOL Kaseya VSA version with ConnectWise ManagedITSync, disconnect it from the network immediately; no security patch will be provided for EOL software.
-
Migrate to Kaseya VSA 10 or alternative RMM — migrate to a currently supported RMM platform with an active security patch program; evaluate Kaseya VSA 10 (cloud-hosted) or alternative MSP RMM platforms (NinjaRMM, ConnectWise Automate, Datto RMM).
-
Audit for compromise indicators — if CVE-2017-18362 may have been exploited, treat all managed endpoints as potentially compromised; audit for unexpected scripts, scheduled tasks, and software deployments pushed via VSA.
-
Restrict RMM access — regardless of platform, ensure MSP RMM management interfaces are never internet-accessible; require VPN or allowlisted IP access for all administrator connections.
-
Enable MFA on all RMM admin accounts — MSP management platforms must have multi-factor authentication on all administrator accounts to limit the impact of credential theft.
Key Details
| Property | Value |
|---|---|
| CVE ID | CVE-2017-18362 |
| Vendor / Product | Kaseya — Virtual System/Server Administrator (VSA) |
| NVD Published | 2019-02-05 |
| NVD Last Modified | 2025-11-05 |
| CVSS 3.1 Score | 9.8 |
| CVSS 3.1 Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Severity | CRITICAL |
| CWE | CWE-89 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') find similar ↗ |
| CISA KEV Added | 2022-05-24 |
| CISA KEV Deadline | 2022-06-14 |
| Known Ransomware Use | ⚠️ Yes |
CVSS 3.1 Breakdown
Required Action
Timeline
| Date | Event |
|---|---|
| 2018-11-07 | ConnectWise releases patched version of ManagedITSync plugin for Kaseya VSA |
| 2019-02-05 | CVE-2017-18362 published by NVD |
| 2022-05-24 | Added to CISA Known Exploited Vulnerabilities catalog |
| 2022-06-14 | CISA BOD 22-01 remediation deadline |
References
| Resource | Type |
|---|---|
| NVD — CVE-2017-18362 | Vulnerability Database |
| CISA KEV Catalog Entry | US Government |
| ConnectWise Security Bulletin — ManagedITSync Plugin Vulnerability | Vendor Advisory |