Quest KACE SMA flaw CVE-2025-32975: when one unpatched tool opens the door to 60 organizations
ID: cb51dc0f-fe72-5161-8cf4-97ef1c9b68d8
STIX ID: report--cb51dc0f-fe72-5161-8cf4-97ef1c9b68d8
Feed Name: Security Affairs
Threat Score
A critical authentication-bypass flaw (CVE-2025-32975, CVSS 10.0) in Quest KACE SMA was left unpatched for ten months and was exploited to compromise MSP HIQ, resulting in a publicly accessible 308 MB attacker toolkit and exfiltration of a 512 MB MariaDB dump that exposed endpoint inventories for over 60 client organizations; researchers published IoCs and a patch has been available since May 2025.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
