CVE-2025-32975: Quest KACE SMA SSO Authentication Bypass Enables Admin Takeover
ID: 7b3e833e-f535-5395-81e8-9a7d7e29a655
STIX ID: report--7b3e833e-f535-5395-81e8-9a7d7e29a655
Feed Name: SOCRadar Blog
CVE-2025-32975 is a critical (CVSS 10.0) SSO authentication bypass in Quest KACE Systems Management Appliance that allows unauthenticated user impersonation and can lead to administrative takeover; affected 13.0–14.1 builds are listed with fixed builds noted, and Quest warns 13.x hotfixes must be re-applied after full upgrades. Researchers observed likely exploitation of internet-exposed, unpatched appliances in March 2026 with post-compromise behaviors including remote command execution via KACE, creation of admin accounts, credential-theft tooling (e.g., Mimikatz), discovery, and lateral movement; defenders are advised to patch to fixed builds, remove internet exposure or restrict access, and hunt for IoCs such as new admin accounts, Base64 payloads, and unexpected KACE activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
