CVE-2017-18362: Kaseya VSA 2017 ConnectWise ManagedITSync – Remote Code Execution

CVE-2017-18362: Kaseya VSA 2017 ConnectWise ManagedITSync - Remote Code Execution-渗透云记 - 专注于网络安全与技术分享
CVE-2017-18362: Kaseya VSA 2017 ConnectWise ManagedITSync – Remote Code Execution
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2017-18362: Kaseya VSA 2017 ConnectWise ManagedITSync – Remote Code Execution

漏洞描述

ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database. If the ManagedIT.asmx page is available via the Kaseya VSA web interface, anyone with access to the page is able to run arbitrary SQL queries, both read and write, without authentication.In February 2019, attackers actively exploited this vulnerability in the wild to download and execute ransomware payloads on all endpoints managed by the VSA server.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享