惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Y
Y Combinator Blog
IT之家
IT之家
博客园_首页
量子位
博客园 - 三生石上(FineUI控件)
小众软件
小众软件
博客园 - 聂微东
罗磊的独立博客
酷 壳 – CoolShell
酷 壳 – CoolShell
Hugging Face - Blog
Hugging Face - Blog
V
V2EX
爱范儿
爱范儿
大猫的无限游戏
大猫的无限游戏
宝玉的分享
宝玉的分享
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
雷峰网
雷峰网
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Google DeepMind News
Google DeepMind News
Microsoft Azure Blog
Microsoft Azure Blog
有赞技术团队
有赞技术团队
S
SegmentFault 最新的问题
Engineering at Meta
Engineering at Meta
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com

Cyberwarzone

LinkedIn Sued Over Browser Extension Scanning Why Cyberwarfare Uses Ambiguity and Delayed Attribution as Pressure Why Cyberwarfare Pressures Trusted Access and Account Recovery Paths Why Cyberwarfare Keeps Pressuring Recovery Paths and Fallback Systems Why Cyberwarfare Keeps Pressuring Shared Service Providers Why Cyberwarfare Pressures Industry Clusters Why Cyberwarfare Turns Nearby Economies Into Spillover Zones Why Cyberwarfare Forces Firms to Scan Networks Early Why Cyberwarfare Targets Crisis Messaging Systems Why Cyberwarfare Keeps Pressuring Energy Networks Why Cyberwarfare Keeps Pressuring Communications Networks Why Cyberwarfare Keeps Pressuring Shipping and Logistics Networks Why Cyberwarfare Keeps Pressuring Banks and Financial Networks Why Endpoint Management Systems Are Becoming Cyberwarfare Choke Points Why Cyberwarfare Targets Healthcare and Medical Supply Chains Why Cyberwarfare Increasingly Exploits Trusted Civilian Apps Why Cyberwarfare Hits Civilian Companies First Handala Rebounds After FBI Seizure, Exposing Iran Cyberwar Resilience Top 10 Cyber Escalation Risks Security Leaders Should Understand Top 10 Questions to Ask Before Calling an Incident Cyberwarfare Top 10 Cyber Deterrence Problems Security Leaders Should Understand Top 10 OT and ICS Risks in Modern Cyberwarfare Top 10 Cyberwarfare Doctrine Ideas Security Leaders Should Understand Top 10 Attribution Problems in State-Linked Cyber Operations Iran Cyberwar: Identity Systems Become the Target Iran Cyberwar Shifts to Spillover, Retaliation, and Control Top 10 Critical Infrastructure Sectors Most Exposed in Cyberwarfare Top 10 Below-Threshold Cyber Operations States Use Top 10 Differences Between Cyberwarfare and Cyber Espionage Top 10 Signs a Cyber Campaign Is Pre-Positioning for Future Conflict
Critical Quest KACE SMA RCE (CVE-2025-32975) Under Attack
Peter Chofield · 2026-03-24 · via Cyberwarzone

Threat actors are actively exploiting CVE-2025-32975, a critical path traversal vulnerability in Quest KACE Systems Management Appliance (SMA), to achieve unauthenticated remote code execution (RCE). The flaw carries a maximum CVSS v3.1 score of 10.0, indicating its severe impact.

The vulnerability was discovered and disclosed by Assetnote researchers on February 28, 2026. Quest subsequently released patches for the affected software on March 18, 2026.

CVE-2025-32975: Unauthenticated Remote Code Execution Details

CVE-2025-32975 is a path traversal vulnerability located in the /agent/agentless_update.php endpoint of the Quest KACE SMA. This flaw allows an unauthenticated attacker to upload arbitrary files to publicly accessible locations on the appliance. By uploading a malicious PHP file, attackers can execute arbitrary code with root privileges.

The vulnerability can be leveraged by unauthenticated attackers to execute arbitrary code with root privileges on affected KACE SMA appliances. The impact of this vulnerability is severe, as it allows full control over the appliance, which often manages a large number of endpoints in an organization.

— Assetnote researchers

The exploit chain bypasses authentication mechanisms, granting attackers full control over the compromised appliance. Given that KACE SMA devices manage numerous endpoints within an organization, successful exploitation poses a significant risk of broader network compromise, similar to other unauthenticated arbitrary file upload vulnerabilities.

Affected Versions and Remediation

The vulnerability impacts Quest KACE SMA versions 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, and 12.0. Users are strongly advised to update their appliances to version 12.1 or later to mitigate the risk of exploitation and ensure proof of remediation.

About the Author

Peter Chofield Avatar

Peter Chofield

Passionate about cybersecurity, Peter dedicates his days to reading, analyzing, and writing about the trends shaping the online world.