CVE-2021-44031: Malicious File Upload
Published Dec 22, 2021
·Updated
An issue was discovered in Quest KACE Desktop Authority before 11.2. /dacomponentui/profiles/profileitems/outlooksettings/Insertimage.aspx contains a vulnerability that could allow pre-authentication remote code execution. An attacker could upload a .ASP file to reside at /images/{GUID}/{filename}.
Affected Software
1 affected component
Quest KACE Desktop Authority<11.2
Event History
Dec 22, 2021
CVE Published
via MITRE·05:08 AM
Data Sourced
via MITRE·05:08 AM
Description
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-44031.
2
What is the severity of CVE-2021-44031?
The severity of CVE-2021-44031 is critical with a CVSS score of 9.8.
3
What is the affected software?
The affected software is Quest KACE Desktop Authority version up to and excluding 11.2.
4
What is the impact of this vulnerability?
This vulnerability could allow pre-authentication remote code execution.
5
Is there a fix available for CVE-2021-44031?
Yes, an update to Quest KACE Desktop Authority version 11.2 or later is available to fix this vulnerability.