Critical Quest KACE Flaw Exploited for Total Network Takeover
ID: bdd70161-4e65-564a-909f-ac74d3394430
STIX ID: report--bdd70161-4e65-564a-909f-ac74d3394430
Feed Name: securityonline.info
Arctic Wolf warns of active exploitation of CVE-2025-32975, a critical SSO authentication bypass in Quest KACE Systems Management Appliances that enables immediate administrative takeover; attackers have used the appliance's RunProcess feature to execute Base64 payloads, create domain-admin accounts, run Mimikatz for credential harvesting, and move laterally to backup and domain controller systems. Although patches were released in May 2025 for affected versions, many Internet-exposed appliances remain vulnerable — organisations are advised to patch, avoid direct Internet exposure, and restrict remote access via VPN or firewall.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
