logo

CVE-2025-32975: Quest KACE SMA SSO Authentication Bypass Enables Admin Takeover

ID: 7b3e833e-f535-5395-81e8-9a7d7e29a655

STIX ID: report--7b3e833e-f535-5395-81e8-9a7d7e29a655

Feed Name: SOCRadar Blog

Threat Score
90/100

Date Published: 2026-03-23

Date Updated: 2026-04-30

Author: Ameer Owda

...
...

CVE-2025-32975 is a critical (CVSS 10.0) SSO authentication bypass in Quest KACE Systems Management Appliance that allows unauthenticated user impersonation and can lead to administrative takeover; affected 13.0–14.1 builds are listed with fixed builds noted, and Quest warns 13.x hotfixes must be re-applied after full upgrades. Researchers observed likely exploitation of internet-exposed, unpatched appliances in March 2026 with post-compromise behaviors including remote command execution via KACE, creation of admin accounts, credential-theft tooling (e.g., Mimikatz), discovery, and lateral movement; defenders are advised to patch to fixed builds, remove internet exposure or restrict access, and hunt for IoCs such as new admin accounts, Base64 payloads, and unexpected KACE activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.