Description
The '/common/ajax_email_connection_test.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by any authenticated user and can be abused to execute arbitrary commands on the system. This script is vulnerable to command injection via the unsanitized user input 'TEST_SERVER' sent to the script via the POST method.
In plain language
AI Worth attentionIf you run Quest KACE System Management Appliance 8.0.318, a logged-in user can abuse an email-testing page to run commands on the appliance, so you should act but this isn’t confirmed as a widely automated attack yet.
In Quest KACE System Management Appliance 8.0.318, the /common/ajax_email_connection_test.php endpoint is vulnerable to command injection via the unsanitized POST parameter TEST_SERVER, and it can be reached by any authenticated user; no official fix details are available from the sources.
What to do now
- Confirm whether you are running Quest KACE System Management Appliance 8.0.318 (check the appliance version in the product’s system/about page).
- Determine whether the vulnerable endpoint is reachable by any users you consider low-trust (for example, non-admin accounts used for everyday tasks).
- Temporarily reduce access: limit which accounts can log into the appliance, and remove or disable accounts that don’t need access.
- If possible in your setup, restrict network access to the KACE web interface so only your admin network/VPN can reach it.
- Look for an upgrade from Quest that addresses CVE-2018-11139; since no fixed version is provided in the available patch info, contact Quest support for the specific fixed build for your branch.
- After changes, monitor the KACE appliance logs for suspicious activity around the /common/ajax_email_connection_test.php endpoint and unexpected command/execution-related events.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2018-11139 and every CVE in our database. Create a free account — no credit card required.
Create Free Account