S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Oct 24, 2025

CVE-2017-18362 Scanner

CVE-2017-18362 Scanner - Remote Code Execution vulnerability in Kaseya VSA ConnectWise ManagedITSync

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3.1k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.
Description

ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database. In February 2019, attackers have actively exploited this in the wild to download and execute ransomware payloads on all endpoints managed by the VSA server. If the ManagedIT.asmx page is available via the Kaseya VSA web interface, anyone with access to the page is able to run arbitrary SQL queries, both read and write, without authentication.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Sep 18, 2026View on NVD →
Detail

The Kaseya VSA ConnectWise ManagedITSync is a widely utilized integration tool used by IT service management and managed service providers to synchronize data between Kaseya VSA and ConnectWise. This software is primarily used to enhance functionalities, streamline operations, and manage extensive IT infrastructures effectively. IT professionals and organizations leverage this integration to automate tasks, process incidents, synchronize configuration items, and ensure seamless accountability in service delivery. It is designed to improve operational efficiencies, reduce manual efforts, and enhance the overall service delivery quality for managed services. The integration also provides extensive reporting capabilities, thus allowing for better tracking and insights into infrastructure management.

Remote Code Execution (RCE) vulnerability allows an attacker to remotely execute arbitrary code on a target system or network. In this specific case with Kaseya VSA ConnectWise ManagedITSync, the vulnerability was associated with unauthenticated remote commands on the managed interface. This indicates a potential path for attackers to execute unwanted commands, manipulate database entries, or even deploy malicious payloads. As RCE is critical in nature, attackers gaining such access could lead to severe impacts including unauthorized access to sensitive data, full control of systems, and potential lateral movement within a network.

The vulnerability in question is notably linked to how the ManagedIT.asmx page of ConnectWise ManagedITSync handles SQL queries. With the vulnerability discovered in the 2017 version of Kaseya VSA, attackers were able to exploit unauthenticated remote commands to run arbitrary SQL queries. The problematic endpoint, ManagedIT.asmx, when exposed, could be accessed by anyone who could then issue SQL commands without authentication, making both read and write database operations vulnerable. This indicates poor input validation and inadequate security measures on key web service pages exposed through the Kaseya interface.

When exploited by malicious actors, this vulnerability can have dire consequences for any organization using Kaseya VSA. Possible effects include unauthorized access to the database with capabilities to read, alter, or delete data. This could lead to significant data breaches, data loss, and corruption of organizational data, undermining business operations and data integrity. Additionally, in practice, it was noted that attackers could use this vulnerability as an entry point for deploying ransomware payloads, causing significant operational and reputational damage, and potential financial loss through ransom payments.

REFERENCES

Solution Advice
  • Update the Kaseya VSA application and related integrations to the latest version to mitigate vulnerabilities.
  • Ensure that ManagedIT.asmx or similar pages are secured and involve stringent authorization checks.
  • Implement robust input validation and sanitization on the application to prevent unauthorized SQL injection.
  • Conduct regular security audits to detect and address possible security flaws in integrations.
  • Monitor network activities and log unusual access patterns for early detection of possible exploitation attempts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2017-18362 Scanner - Remote Code Execution vulnerability in Kaseya VSA ConnectWise ManagedITSync | S4E