March 25, 2022 · Applied Cybernetics Group
CVE-2018-11138 — Quest KACE System Management Appliance
known ransomware use
Quest KACE System Management Appliance Remote Command Execution Vulnerability
- Added to KEV
2022-03-25- Federal due date
2022-04-15- Vendor
- Quest
- Product
- KACE System Management Appliance
- EPSS
- 99.8th percentile (score 0.921, as of
2026-09-16) - NVD CVSS v3.1
- 9.8 (CRITICAL)
- Ransomware use
- Known
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2018-11138
CISA short description
The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance is accessible by anonymous users and can be abused to perform remote code execution.
Required action
Apply updates per vendor instructions.
NVD description
The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users and can be abused to execute arbitrary commands on the system.