Description
In order to perform actions that requires higher privileges, the Quest KACE System Management Appliance 8.0.318 relies on a message queue managed that runs with root privileges and only allows a set of commands. One of the available commands allows changing any user's password (including root). A low-privilege user could abuse this feature by changing the password of the 'kace_support' account, which comes disabled by default but has full sudo privileges.
In plain language
AI Worth attentionCVE-2018-11134 is a way for someone with a low-level account to secretly switch a disabled admin support account’s password and take complete control of the Quest KACE System Management Appliance; this is a serious risk, especially since the vulnerable access is reachable by default.
In Quest KACE System Management Appliance, a low-privileged authenticated attacker can abuse a privileged internal message-queue command to change the password of a disabled full-administrative support account, effectively enabling a hidden super-user path and leading to full system takeover (CWE-640).
What to do now
- Check whether your Quest KACE System Management Appliance is reachable from the network and whether any low-privilege accounts are known/accessible.
- Verify your appliance version: confirm you are running Quest KACE System Management Appliance 8.0.318.
- Check with Quest/vendor support for mitigation or an available update for CVE-2018-11134 (no fixed version was identified in the provided information).
- Immediately restrict network access to the appliance to only trusted admin IPs/VPNs, and review/lock down any low-privilege user accounts that could be abused to trigger this issue.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2018-11134 and every CVE in our database. Create a free account — no credit card required.
Create Free Account