Arbitrary File Creation Vulnerability in Quest KACE Agent for Windows
CVE-2024-23772

Currently unrated

Key Information:

Vendor

Quest

Vendor
CVE Published:
30 April 2024

What is CVE-2024-23772?

A vulnerability exists in the Quest KACE Agent for Windows, affecting versions 12.0.38 and 13.1.23.0, due to issues within the KSchedulerSvc.exe, KUserAlert.exe, and Runkbot.exe components. This allows local attackers to exploit the system, enabling them to create any file of their choice with NT Authority\SYSTEM privileges, potentially leading to unauthorized access and system compromise.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

Timeline

  • Vulnerability published

.