logo

CVE-2017-18362: Arbitrary SQL Execution in ManagedITSync Integration

ID: be94b19b-a708-5179-a7ef-d6615df6d600

STIX ID: report--be94b19b-a708-5179-a7ef-d6615df6d600

Feed Name: Huntress Blog

Threat Score
85/100

Date Published: 2019-02-08

Date Updated: 2026-04-28

...
...

A SQL-injection vulnerability in the ConnectWise ManagedITSync integration for on‑premises Kaseya VSA allows remote attackers to execute arbitrary SQL (create admin users, change passwords, and create tasks). The report documents active exploitation that leveraged this flaw to deploy GandCrab ransomware across MSP-managed endpoints, explains who is vulnerable, how to check for the integration or vulnerable files, and advises immediate mitigations (disconnect VSA, audit systems, remove/update the integration).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.