Arbitrary File Creation Vulnerability in Quest KACE Agent for Windows
CVE-2024-23772
Currently unrated
What is CVE-2024-23772?
A vulnerability exists in the Quest KACE Agent for Windows, affecting versions 12.0.38 and 13.1.23.0, due to issues within the KSchedulerSvc.exe, KUserAlert.exe, and Runkbot.exe components. This allows local attackers to exploit the system, enabling them to create any file of their choice with NT Authority\SYSTEM privileges, potentially leading to unauthorized access and system compromise.