LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2018-11138: Quest KACE System Management Appliance Remote Command Execution Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 25, 2022
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Apr 15, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2018-11138 to its Known Exploited Vulnerabilities catalog on Mar 25, 2022, with a federal patch deadline of Apr 15, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance is accessible by anonymous users and can be abused to perform remote code execution.

How it works

CVE-2018-11138 is a remote command execution flaw in the Quest KACE System Management Appliance. It stems from CWE-78 (OS command injection). According to the CISA summary, the script at /common/download_agent_installer.php is reachable by anonymous users and can be abused to run commands on the appliance.

In this class of weakness, user-controlled input reaches a shell or similar interpreter without proper validation or escaping. An unauthenticated attacker who can reach the script can supply crafted input that the appliance treats as part of an operating-system command. Successful abuse gives the attacker the ability to execute arbitrary commands in the context of the vulnerable service. Exact parameter names, payloads, and preconditions are not detailed here; confirm those against the vendor advisory.

Am I affected? How to find it in your systems

Quest KACE System Management Appliance (also known as KACE SMA) is typically deployed as a network appliance or virtual appliance used for endpoint inventory, software distribution, and related systems-management tasks. It often sits on management or internal networks and may be reachable from broader segments if access controls are loose.

Inventory steps:

Telemetry and log signs of exploitation (general for this class): unexpected requests to /common/download_agent_installer.php, especially from external or unusual internal sources; command-shell or process-creation events spawned by the web service account; sudden outbound connections or new local accounts following such requests. Correlate web-access logs with host-based process and network logs. Absence of these signs does not prove safety if the appliance was reachable and unpatched.

How to remediate

Patch first. CISA’s required action is to apply updates per vendor instructions. Obtain the fixed release or patch package from Quest for the KACE System Management Appliance, validate it in a test environment if possible, then deploy it to production appliances and verify the build string afterward.

After patching, harden for this weakness class:

If you can't patch immediately

Until the vendor update is applied, reduce exposure with compensating controls:

These measures lower risk but do not replace the vendor patch. Schedule the update as soon as practicable.

If your data may have been exposed

This vulnerability has known ransomware use. Actively exploited remote-command-execution flaws on management appliances frequently lead to full compromise, lateral movement, data theft, or ransomware deployment. If your KACE SMA was reachable and unpatched during the period of exposure, treat it as a potential incident: isolate the host, preserve logs and disk images, hunt for persistence and follow-on activity, and follow your incident-response plan. As a further check, you can run a free exposure scan of your email addresses against known breach data to see whether associated credentials or identities have appeared in public breach corpora.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedQuest · KACE System Management Appliance
WeaknessCWE-78
Added to CISA KEVMar 25, 2022
Federal patch deadlineApr 15, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities