CVE-2024-23772

An issue was discovered in Quest KACE Agent for Windows 12.0.38 and 13.1.23.0. An Arbitrary file create vulnerability exists in the KSchedulerSvc.exe, KUserAlert.exe, and Runkbot.exe components. This allows local attackers to create any file of their choice with NT Authority\SYSTEM privileges.
Configurations

No configuration.

History

21 Nov 2024, 08:58

Type Values Removed Values Added
References () https://support.quest.com/kb/4375402/quest-response-to-kace-sma-agent-vulnerabilities-cve-2024-23772-cve-2024-23773-cve-2024-23774 - () https://support.quest.com/kb/4375402/quest-response-to-kace-sma-agent-vulnerabilities-cve-2024-23772-cve-2024-23773-cve-2024-23774 -
References () https://www.quest.com/kace/ - () https://www.quest.com/kace/ -

09 Aug 2024, 21:35

Type Values Removed Values Added
Summary
  • (es) Se descubrió un problema en Quest KACE Agent para Windows 12.0.38 y 13.1.23.0. Existe una vulnerabilidad de creación de archivos arbitrarios en los componentes KSchedulerSvc.exe, KUserAlert.exe y Runkbot.exe. Esto permite a los atacantes locales crear cualquier archivo de su elección con privilegios NT Authority\SYSTEM.
CWE CWE-22
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.6

30 Apr 2024, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-30 14:15

Updated : 2024-11-21 08:58


NVD link : CVE-2024-23772

Mitre link : CVE-2024-23772

CVE.ORG link : CVE-2024-23772


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')