Vulnerabilities
Vulnerable Software
Quest:  >> Kace Desktop Authority  Security Vulnerabilities
An issue was discovered in Quest KACE Desktop Authority before 11.2. This vulnerability allows attackers to execute remote code through a deserialization exploitation in the RadAsyncUpload function of ASP.NET AJAX. An attacker can leverage this vulnerability when the encryption keys are known (due to the presence of CVE-2017-11317, CVE-2017-11357, or other means). A default setting for the type whitelisting feature in more current versions of ASP.NET AJAX prevents exploitation.
CVSS Score
9.8
EPSS Score
0.009
Published
2021-12-22
Quest KACE Desktop Authority before 11.2 allows XSS because it does not prevent untrusted HTML from reaching the jQuery.htmlPrefilter method of jQuery.
CVSS Score
6.1
EPSS Score
0.005
Published
2021-12-22
An issue was discovered in Quest KACE Desktop Authority before 11.2. /dacomponentui/profiles/profileitems/outlooksettings/Insertimage.aspx contains a vulnerability that could allow pre-authentication remote code execution. An attacker could upload a .ASP file to reside at /images/{GUID}/{filename}.
CVSS Score
9.8
EPSS Score
0.035
Published
2021-12-22
XXE can occur in Quest KACE Desktop Authority before 11.2 because the log4net configuration file might be controlled by an attacker, a related issue to CVE-2018-1285.
CVSS Score
5.5
EPSS Score
0.002
Published
2021-12-22


Contact Us

Shodan ® - All rights reserved