CVE-2018-11138
CISA 기관 조치 기한: 2022-04-15
Quest KACE System Management Appliance
The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance is accessible by anonymous users and can be abused to perform remote code execution.
KEV 필수 조치: Apply updates per vendor instructions.
공개 익스플로잇 / PoC
- Exploit-DB: EDB-44950 ↗