PT-2026-2270 · Quest · Kace Desktop Authority

Published

2026-01-12

·

Updated

2026-03-10

·

CVE-2025-67813

CVSS v3.1

5.3

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Quest KACE Desktop Authority versions through 11.3.1
Description Quest KACE Desktop Authority through version 11.3.1 has insecure permissions on the Named Pipes used for inter-process communication. Named Pipes are used to enable communication between different processes on a system. Insecure permissions on these pipes could allow unauthorized access or manipulation of data.
Recommendations Update Quest KACE Desktop Authority to a version later than 11.3.1.

Fix

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

CVE-2025-67813

Affected Products

Kace Desktop Authority