Junglewise Threat Intelligence

CVE-2018-11138: Quest KACE System Management Appliance Remote Command Execution Vulnerability

CVE-2018-11138 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-03-25

Vendors: Quest.

Executive brief

The '/common/download_agent_installer.php' script in Quest KACE System Management Appliance allows anonymous users to execute arbitrary commands on the system. This OS command injection vulnerability can be exploited remotely without authentication.

Affected products

  • Quest KACE System Management Appliance 8.0.318

Timeline

  • 2018-05-31: disclosed: NVD Published Date
  • 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-04-15: other: CISA due date for remediation