PoC Index

CVE-2018-11132

HIGH 9.0EPSS 18.3%

In order to perform actions that require higher privileges, the Quest KACE System Management Appliance 8.0.318 relies on a message queue that runs daemonized with root privileges and only allows a set of commands to be executed. A command injection vulnerability exists within this message queue which allows low-privilege users to append arbitrary commands that will be run as root.

CVSS v3.0
8.8 HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
9.0 HIGHAV:N/AC:L/Au:S/C:C/I:C/A:C
EPSS
18.29% chance of exploitation in the next 30 days, 97th percentile
Published
2018-05-31
Updated
2024-08-05

Proof-of-concept exploits (1)

References

Related