CVE-2018-11132: OS Command Injection
In order to perform actions that require higher privileges, the Quest KACE System Management Appliance 8.0.318 relies on a message queue that runs daemonized with root privileges and only allows a set of commands to be executed. A command injection vulnerability exists within this message queue which allows low-privilege users to append arbitrary commands that will be run as root.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-11132?
CVE-2018-11132 is classified as a high-severity command injection vulnerability.
How do I fix CVE-2018-11132?
To mitigate CVE-2018-11132, update your Quest KACE System Management Appliance to the latest version provided by the vendor.
What are the risks associated with CVE-2018-11132?
Exploitation of CVE-2018-11132 can lead to unauthorized command execution with root privileges.
Which versions are affected by CVE-2018-11132?
CVE-2018-11132 affects Quest KACE System Management Appliance version 8.0.318.
How can I identify if my system is vulnerable to CVE-2018-11132?
Check your installed version of Quest KACE System Management Appliance; if it is 8.0.318, your system is vulnerable to CVE-2018-11132.