logo

Critical Quest KACE Flaw Exploited for Total Network Takeover

ID: bdd70161-4e65-564a-909f-ac74d3394430

STIX ID: report--bdd70161-4e65-564a-909f-ac74d3394430

Feed Name: securityonline.info

Threat Score
88/100

Date Published: 2026-03-20

Date Updated: 2026-04-23

Author: Ddos

...
...

Arctic Wolf warns of active exploitation of CVE-2025-32975, a critical SSO authentication bypass in Quest KACE Systems Management Appliances that enables immediate administrative takeover; attackers have used the appliance's RunProcess feature to execute Base64 payloads, create domain-admin accounts, run Mimikatz for credential harvesting, and move laterally to backup and domain controller systems. Although patches were released in May 2025 for affected versions, many Internet-exposed appliances remain vulnerable — organisations are advised to patch, avoid direct Internet exposure, and restrict remote access via VPN or firewall.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.