Description
In order to perform actions that require higher privileges, the Quest KACE System Management Appliance 8.0.318 relies on a message queue that runs daemonized with root privileges and only allows a set of commands to be executed. A command injection vulnerability exists within this message queue which allows low-privilege users to append arbitrary commands that will be run as root.
In plain language
AI Worth attentionQuest KACE System Management Appliance 8.0.318 lets a logged-in low-level user take full control of the appliance, so businesses using that version should act soon.
Authenticated command injection (CWE-78) in the root-privileged message queue of Quest KACE System Management Appliance 8.0.318 permits low-privilege users to execute arbitrary commands as root.
What to do now
- Check whether you run Quest KACE System Management Appliance and whether its version is 8.0.318.
- Review low-level user accounts and remove accounts that are no longer needed.
- No fixed version has been published; ask Quest for a supported update or mitigation for CVE-2018-11132.
- Limit access to the appliance to trusted administrators and networks until Quest provides guidance.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2018-11132 and every CVE in our database. Create a free account — no credit card required.
Create Free Account