Back

CRITICAL KEV Used in ransomware campaigns

ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database

Published Feb 5, 2019 ·Due Jun 14, 2022

Description

ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database. In February 2019, attackers have actively exploited this in the wild to download and execute ransomware payloads on all endpoints managed by the VSA server. If the ManagedIT.asmx page is available via the Kaseya VSA web interface, anyone with access to the page is able to run arbitrary SQL queries, both read and write, without authentication.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Feb 5, 2019
Updated Aug 13, 2026
Reserved Feb 4, 2019
CISA Vulnrichment
Updated Feb 4, 2025
NVD
Status Analyzed
Modified Aug 13, 2026
Red Hat
Severity n/a
Public date n/a