logo

Hackers Exploit CVE-2025-32975 (CVSS 10.0) to Hijack Unpatched Quest KACE SMA Systems

ID: 2f443971-259d-589b-a48b-ebba4b8e2d6c

STIX ID: report--2f443971-259d-589b-a48b-ebba4b8e2d6c

Feed Name: The Hacker News

Threat Score
88/100

Date Published: 2026-03-23

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Arctic Wolf reported malicious activity beginning the week of March 9, 2026 exploiting CVE-2025-32975 (authentication bypass, CVSS 10.0) in internet-exposed Quest KACE SMA instances. Threat actors used the flaw to seize administrative accounts, execute remote commands to retrieve Base64-encoded payloads from 216.126.225.156, create additional admin accounts via runkbot.exe, modify the Windows Registry for persistence, harvest credentials with Mimikatz, and gain RDP access to backup systems and domain controllers; vendors have patched the issue and administrators are advised to update and avoid exposing SMA to the internet.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.