CVE-2018-11138—Quest KACE System Management Appliance Remote Command Execution Vulnerability
PUBLISHEDvulnerability record
2022-03-25 · last modified June 21, 2025
Metadata
Vulnerability Name
Quest KACE System Management Appliance Remote Command Execution Vulnerability
Description
The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance is accessible by anonymous users and can be abused to perform remote code execution.
Known To Be Used in Ransomware Campaigns?
Action
Apply updates per vendor instructions.