CVE-2018-11138
KEV ransomware PoC ×2largeUnauthenticated RCE in Quest KACE System Management Appliance
CISA: Quest KACE System Management Appliance Remote Command Execution Vulnerability
An unauthenticated operating-system command injection (CWE-78) exists in the /common/download_agent_installer.php script of the Quest KACE System Management Appliance, confirmed in version 8.0.318. Because the script is reachable by anonymous users over the network, a remote attacker with no credentials can send crafted input that the script passes to the underlying shell, executing arbitrary commands on the appliance. Successful exploitation gives the attacker high-impact control of the appliance (confidentiality, integrity, and availability all rated high), a foothold that can be used to pivot into managed endpoints and harvest stored credentials. Any organization running a Quest KACE SMA is affected, with actual exposure depending on whether the appliance's web interface is reachable from untrusted networks. The flaw is under active exploitation: it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-25 with known ransomware use, and EPSS assigns a 92.1% probability of exploitation within 30 days.
What to do: Upgrade the KACE System Management Appliance per Quest's update instructions, as required by the CISA KEV catalog (the specific fixed version is not stated in the available data). As an interim mitigation, restrict unauthenticated access to /common/download_agent_installer.php (e.g., via ACL or reverse proxy) and limit the appliance's web interface to trusted management networks. Verify the running appliance version and review web logs for anonymous requests to download_agent_installer.php with unusual parameters, given documented ransomware exploitation.
| Quest KACE System Management Appliance | 8.0.318 (version cited in the advisory; the full affected/fixed version range is not specified in the available data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users and can be abused to execute arbitrary commands on the system.
- Affected
- Quest KACE System Management Appliance
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- quest
- Products
- kace system management appliance
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.