CVE-2018-11138Quest KACE System Management Appliance Remote Command Execution Vulnerability

PUBLISHEDvulnerability record
2022-03-25 · last modified June 21, 2025

Metadata

CVE ID:
CVE-2018-11138
Project:
Quest
Product:
KACE System Management Appliance
Date Added:
2022-03-25
Due Date:
2022-04-15
Last Updated:
June 21, 2025

Vulnerability Name

Quest KACE System Management Appliance Remote Command Execution Vulnerability

Description

The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance is accessible by anonymous users and can be abused to perform remote code execution.

Known To Be Used in Ransomware Campaigns?

Ransomware Status:
KNOWN

Action

Apply updates per vendor instructions.

Additional Notes

Related Weaknesses