CVE-2024-23774
HIGH 7.8EPSS 0.4%
An issue was discovered in Quest KACE Agent for Windows 12.0.38 and 13.1.23.0. An unquoted Windows search path vulnerability exists in the KSchedulerSvc.exe and AMPTools.exe components. This allows local attackers to execute code of their choice with NT Authority\SYSTEM privileges.
- CVSS v3.1
- 7.8 HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - EPSS
- 0.44% chance of exploitation in the next 30 days, 37th percentile
- Published
- 2024-04-30
- Updated
- 2024-08-01
Proof-of-concept exploits (1)
- Verrideo/CVE-2024-237740★ · 2024-02-05