Hackers Exploit CVE-2025-32975 (CVSS 10.0) to Hijack Unpatched Quest KACE SMA Systems
ID: 2f443971-259d-589b-a48b-ebba4b8e2d6c
STIX ID: report--2f443971-259d-589b-a48b-ebba4b8e2d6c
Feed Name: The Hacker News
Arctic Wolf reported malicious activity beginning the week of March 9, 2026 exploiting CVE-2025-32975 (authentication bypass, CVSS 10.0) in internet-exposed Quest KACE SMA instances. Threat actors used the flaw to seize administrative accounts, execute remote commands to retrieve Base64-encoded payloads from 216.126.225.156, create additional admin accounts via runkbot.exe, modify the Windows Registry for persistence, harvest credentials with Mimikatz, and gain RDP access to backup systems and domain controllers; vendors have patched the issue and administrators are advised to update and avoid exposing SMA to the internet.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
