CISA Known Exploited Vulnerability

CVE-2018-11138 Ransomware

Quest · KACE System Management Appliance

Quest KACE System Management Appliance Remote Command Execution Vulnerability

Date added
BOD 22-01 due date
CWE CWE-78
Ransomware Known

CISA description

The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance is accessible by anonymous users and can be abused to perform remote code execution.

Required action

Apply updates per vendor instructions.