ZeroHour

CVE-2018-11138

KEV ransomware PoC ×2large

Unauthenticated RCE in Quest KACE System Management Appliance

CISA: Quest KACE System Management Appliance Remote Command Execution Vulnerability

CVSS 3.1
9.8 critical
EPSS
92%p100
Published
()
KEV added
AI analysis

An unauthenticated operating-system command injection (CWE-78) exists in the /common/download_agent_installer.php script of the Quest KACE System Management Appliance, confirmed in version 8.0.318. Because the script is reachable by anonymous users over the network, a remote attacker with no credentials can send crafted input that the script passes to the underlying shell, executing arbitrary commands on the appliance. Successful exploitation gives the attacker high-impact control of the appliance (confidentiality, integrity, and availability all rated high), a foothold that can be used to pivot into managed endpoints and harvest stored credentials. Any organization running a Quest KACE SMA is affected, with actual exposure depending on whether the appliance's web interface is reachable from untrusted networks. The flaw is under active exploitation: it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-25 with known ransomware use, and EPSS assigns a 92.1% probability of exploitation within 30 days.

What to do: Upgrade the KACE System Management Appliance per Quest's update instructions, as required by the CISA KEV catalog (the specific fixed version is not stated in the available data). As an interim mitigation, restrict unauthenticated access to /common/download_agent_installer.php (e.g., via ACL or reverse proxy) and limit the appliance's web interface to trusted management networks. Verify the running appliance version and review web logs for anonymous requests to download_agent_installer.php with unusual parameters, given documented ransomware exploitation.

Affected
Quest KACE System Management Appliance8.0.318 (version cited in the advisory; the full affected/fixed version range is not specified in the available data)
Estimated exposure
largetens of thousands of appliance deployments, with a smaller internet-exposed subset likely on the order of thousands — Based on deployment patterns: the KACE SMA is a long-standing on-prem endpoint-management appliance widely used in enterprise, education, and government environments (installed base plausibly in the tens of thousands), while public…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users and can be abused to execute arbitrary commands on the system.

CISA Known Exploited Vulnerability
Affected
Quest KACE System Management Appliance
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
quest
Products
kace system management appliance
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.