RULE(RULE ID:323896)

Rule General Information
Release Date: 2019-11-29
Rule Name: Quest KACE Systems Management Command Injection Vulnerability (CVE-2018-11138)
Severity:
CVE ID:
Rule Protection Details
Description: The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users and can be abused to execute arbitrary commands on the system.
Impact: An attacker can execute arbitrary command via a successful exploit in the context of the vulnerable software.
Affected OS: Windows
Reference: ExploitDB:44950
https://www.coresecurity.com/advisories/quest-kace-system-management-appliance-multiple-vulnerabilities
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
https://support.quest.com/download-install-detail/6086148