Arbitrary File Deletion Vulnerability in Quest KACE Agent for Windows
CVE-2024-23773

Currently unrated

Key Information:

Vendor

Quest

Vendor
CVE Published:
30 April 2024

What is CVE-2024-23773?

The Quest KACE Agent for Windows contains a vulnerability within the KSchedulerSvc.exe component, which allows local attackers to delete any file of their choice due to a flaw in the privilege escalation mechanism. This issue impacts versions 12.0.38 and 13.1.23.0, enabling unauthorized file deletions at the NT Authority\SYSTEM level, thereby posing significant risks to data integrity and system security.

References

Timeline

  • Vulnerability published

.