PT-2025-26740 · Quest · Quest Kace System Management Appliance

Mohamed Mahmoudi

+1

·

Published

2025-06-24

·

Updated

2026-04-26

·

CVE-2025-32975

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Quest KACE Systems Management Appliance (SMA) versions 13.0.x prior to 13.0.385 Quest KACE Systems Management Appliance (SMA) versions 13.1.x prior to 13.1.81 Quest KACE Systems Management Appliance (SMA) versions 13.2.x prior to 13.2.183 Quest KACE Systems Management Appliance (SMA) versions 14.0.x prior to 14.0.341 (Patch 5) Quest KACE Systems Management Appliance (SMA) versions 14.1.x prior to 14.1.101 (Patch 4)
Description An authentication bypass issue exists in the SSO authentication handling mechanism, allowing remote attackers to impersonate legitimate users without valid credentials, which can lead to complete administrative takeover. Technical exploitation involves remote command execution via the KPluginRunProcess() function, using curl to deliver Base64-encoded payloads and establishing persistence through registry changes. This flaw has been actively exploited in real-world incidents, specifically targeting internet-exposed systems and organizations within the education sector, enabling attackers to move laterally to managed endpoints and steal credentials. Other reported issues include errors in cryptographic signature verification allowing the upload of backup files and a lack of authentication for critical functions that could result in a denial of service.
Recommendations Update versions 13.0.x to 13.0.385 or newer. Update versions 13.1.x to 13.1.81 or newer. Update versions 13.2.x to 13.2.183 or newer. Update versions 14.0.x to 14.0.341 (Patch 5) or newer. Update versions 14.1.x to 14.1.101 (Patch 4) or newer. Restrict public internet exposure by using a firewall, VPN, or air-gapping the system.

Fix

RCE

Improper Verification of Cryptographic Signature

Improper Authentication

Missing Authentication

Authentication Bypass Using an Alternate Path or Channel

Weakness Enumeration

Related Identifiers

BDU:2025-10708
BDU:2026-00086
BDU:2026-00087
BDU:2026-00088
CVE-2025-32975

Affected Products

Quest Kace System Management Appliance