Vulnerability Watch

Forum Discussion

scaveza's avatar
scaveza
Product Team
4 years ago

CVE-2021-30116: Multiple Zero-Day Vulnerabilities in Kaseya...

CVE-2021-30116: Multiple Zero-Day Vulnerabilities in Kaseya VSA Exploited to Distribute REvil Ransomware

On July 2, reports emerged that a number of companies whose networks are administered by managed service providers (MSPs) using Kaseya Virtual System Administrator (VSA), a remote monitoring and management (RMM) software from Kaseya Limited, became the victims of a large-scale ransomware attack.

On July 5, Kaseya confirmed that multiple zero-day vulnerabilities were used to target vulnerable VSA server instances, including an authentication bypass flaw and an arbitrary command execution vulnerability. Kaseya is expected to release a patch for customers soon and has instructed Kaseya VSA on-premise customers to shut down their VSA servers until the patch is available.

For more information about the vulnerability, including the availability of patches and Tenable product coverage, please visit our blog.

No RepliesBe the first to reply