CVE-2024-23772: Path Traversal
An issue was discovered in Quest KACE Agent for Windows 12.0.38 and 13.1.23.0. An Arbitrary file create vulnerability exists in the KSchedulerSvc.exe, KUserAlert.exe, and Runkbot.exe components. This allows local attackers to create any file of their choice with NT Authority\SYSTEM privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23772?
CVE-2024-23772 is classified as a high severity vulnerability due to the potential for arbitrary file creation with elevated privileges.
How do I fix CVE-2024-23772?
To mitigate CVE-2024-23772, update the Quest KACE Agent to version 13.1.23.0 or later, or apply any available security patches.
What components are affected by CVE-2024-23772?
CVE-2024-23772 affects the KSchedulerSvc.exe, KUserAlert.exe, and Runkbot.exe components of the Quest KACE Agent.
Who can exploit CVE-2024-23772?
CVE-2024-23772 can be exploited by local attackers with access to the affected system.
What are the potential risks of CVE-2024-23772?
The risks of CVE-2024-23772 include unauthorized file creation and the possibility of system compromise due to elevated privileges.