CVE-2021-44029: Critical severity quest kace desktop authority vulnerability
Published Dec 22, 2021
·Updated
An issue was discovered in Quest KACE Desktop Authority before 11.2. This vulnerability allows attackers to execute remote code through a deserialization exploitation in the RadAsyncUpload function of ASP.NET AJAX. An attacker can leverage this vulnerability when the encryption keys are known (due to the presence of CVE-2017-11317, CVE-2017-11357, or other means). A default setting for the type whitelisting feature in more current versions of ASP.NET AJAX prevents exploitation.
Affected Software
1 affected component
Quest KACE Desktop Authority>=10.0<11.2
Event History
Dec 22, 2021
CVE Published
via MITRE·05:08 AM
Data Sourced
via MITRE·05:08 AM
Description
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeaknessAffected Software