LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2017-18362: Kaseya VSA SQL Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·May 24, 2022
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Jun 14, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2017-18362 to its Known Exploited Vulnerabilities catalog on May 24, 2022, with a federal patch deadline of Jun 14, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

ConnectWise ManagedITSync integration for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database.

CVE-2017-18362 is a SQL injection vulnerability in Kaseya Virtual System/Server Administrator (VSA), specifically involving the ConnectWise ManagedITSync integration. It allows unauthenticated remote commands that grant full direct access to the Kaseya VSA database. This matters because VSA is commonly used for remote monitoring and management; database access can expose credentials, configurations, and managed endpoints, and the issue has known ransomware use. The impacted product is end-of-life.

IT and security teams should treat any remaining instances as high priority for discovery and isolation. Confirm all technical details against the vendor advisory, as public specifics on exact builds and configurations are limited.

How it works

This flaw falls under CWE-89 (SQL Injection). In this class of weakness, untrusted input reaches a database query without proper sanitization or parameterization, letting an attacker alter the intended SQL logic.

According to the CISA summary, the ConnectWise ManagedITSync integration for Kaseya VSA is vulnerable to unauthenticated remote commands. An attacker who can reach the affected interface can issue crafted requests that result in full direct access to the Kaseya VSA database. That access can support reading or modifying data, creating accounts, or otherwise abusing the management platform. Exact request formats and exploit mechanics are not detailed here; treat any internet- or network-exposed VSA instance with this integration as potentially abusable and verify behavior against the vendor advisory.

Am I affected? How to find it in your systems

Kaseya VSA typically runs as an on-premises or hosted remote monitoring and management (RMM) server used by MSPs and internal IT teams to administer endpoints. Inventory steps:

Telemetry and log signs of exploitation (general for this class): unusual or unauthenticated requests hitting integration or database-related endpoints; spikes in SQL errors or anomalous query patterns in application/database logs; unexpected administrative account creation or bulk data access from the VSA host; outbound connections or ransomware-related activity originating from managed endpoints after VSA compromise. Correlate with EDR/SIEM alerts for credential dumping or lateral movement from the VSA server.

How to remediate

CISA states the impacted product is end-of-life and should be disconnected if still in use. That is the primary remediation path: decommission the affected Kaseya VSA instance and the ConnectWise ManagedITSync integration rather than attempting prolonged operation.

Do not rely on partial configuration tweaks alone; end-of-life status means ongoing vendor fixes should not be expected. Confirm final disposition steps with the vendor advisory.

If you can't patch immediately

Because the product is end-of-life, “patch later” is not a viable long-term plan. Until full disconnection:

If your data may have been exposed

Actively exploited vulnerabilities, including those with known ransomware use, frequently lead to data theft and follow-on extortion. If this VSA instance was reachable and unpatched, assume the database and managed systems may have been accessed. Rotate secrets, review accounts and agent configurations, and investigate for persistence or ransomware staging. You can run a free exposure scan of your email addresses against known breach data to check whether associated credentials or identities have appeared in public breach corpora, then proceed with broader incident response as needed.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedKaseya · Virtual System/Server Administrator (VSA)
WeaknessCWE-89
Added to CISA KEVMay 24, 2022
Federal patch deadlineJun 14, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities