CVE-2017-18362: Arbitrary SQL Execution in ManagedITSync Integration
ID: be94b19b-a708-5179-a7ef-d6615df6d600
STIX ID: report--be94b19b-a708-5179-a7ef-d6615df6d600
Feed Name: Huntress Blog
A SQL-injection vulnerability in the ConnectWise ManagedITSync integration for on‑premises Kaseya VSA allows remote attackers to execute arbitrary SQL (create admin users, change passwords, and create tasks). The report documents active exploitation that leveraged this flaw to deploy GandCrab ransomware across MSP-managed endpoints, explains who is vulnerable, how to check for the integration or vulnerable files, and advises immediate mitigations (disconnect VSA, audit systems, remove/update the integration).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
