CVE detail
CVE-2018-11138: Quest KACE System Management Appliance Remote Command Execution Vulnerability
Source: CISA Known Exploited Vulnerabilities catalog · back to feed
Vendor / product
Quest · KACE System Management Appliance
- Date added (KEV)
- Mar 25, 2022
- CISA due date
- Apr 15, 2022
- Ransomware campaign use
- Known
Scorifya interpretation
AI-generatedA short, structured read of the record above, generated when this page first loads, then cached for a week.
Plain English
Technical detail
From CISA
The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance is accessible by anonymous users and can be abused to perform remote code execution.
https://nvd.nist.gov/vuln/detail/CVE-2018-11138
See what attackers can see on your domain
This vulnerability is on CISA's Known Exploited Vulnerabilities list, so it is being exploited in the wild right now, including in ransomware campaigns. Scorifya can't test for Quest directly, but in about 30 seconds it shows what your own domain exposes publicly across TLS, security headers, DNS, and cookies: the surface attackers probe first.
SOC 2 compliance
Tracking remediation across your cloud infrastructure?
Scorifya Controls automates 33 SOC 2 checks across AWS, GitHub, GCP, and Azure, and gives you a manual evidence trail for the controls no tool can automate. Self-hosted, three tiers from $99/mo.
See Scorifya Controls →References
- https://www.coresecurity.com/advisories/quest-kace-system-management-appliance-multiple-vulnerabilitiesExploitTechnical DescriptionThird Party Advisory
- https://www.exploit-db.com/exploits/44950/ExploitThird Party AdvisoryVDB Entry
- https://www.coresecurity.com/advisories/quest-kace-system-management-appliance-multiple-vulnerabilitiesExploitTechnical DescriptionThird Party Advisory
- https://www.exploit-db.com/exploits/44950/Exploit
Other recent CVEs from Quest
- CVE-2025-32975KACE Systems Management Appliance (SMA), Quest KACE Systems Management Appliance (SMA) Improper Authentication Vulnerability