UNKNOWNKNOWN EXPLOITEDRANSOMWARE: KNOWN
CVE-2018-11138
Quest KACE System Management Appliance Remote Command Execution Vulnerability
Summary
The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance is accessible by anonymous users and can be abused to perform remote code execution.
References
Includes data from the CISA Known Exploited Vulnerabilities catalog.
CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.