PT-2018-10333 · Quest · Quest Kace System Management Virtual Appliance

Published

2018-05-31

·

Updated

2018-06-29

·

CVE-2018-11141

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Quest KACE System Management Virtual Appliance version 8.0.318
Description The issue concerns the /adminui/advisory.php script, where the IMAGES JSON and attachments to remove[] parameters can be exploited for Directory Traversal attacks. This allows an attacker to write and delete files, respectively, in any location where the www user has write permissions.
Recommendations For Quest KACE System Management Virtual Appliance version 8.0.318, consider restricting access to the /adminui/advisory.php script until a patch is available. As a temporary workaround, restrict the write permissions of the www user to minimize the risk of exploitation. Avoid using the IMAGES JSON and attachments to remove[] parameters in the affected script until the issue is resolved.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-11141

Affected Products

Quest Kace System Management Virtual Appliance