Arbitrary File Creation Vulnerability in Quest KACE Agent for Windows
CVE-2024-23772

Currently unrated

Key Information:

Vendor

Quest

Vendor
CVE Published:
30 April 2024

What is CVE-2024-23772?

A vulnerability exists in the Quest KACE Agent for Windows, affecting versions 12.0.38 and 13.1.23.0, due to issues within the KSchedulerSvc.exe, KUserAlert.exe, and Runkbot.exe components. This allows local attackers to exploit the system, enabling them to create any file of their choice with NT Authority\SYSTEM privileges, potentially leading to unauthorized access and system compromise.

References

Timeline

  • Vulnerability published

.
CVE-2024-23772 : Arbitrary File Creation Vulnerability in Quest KACE Agent for Windows