CVE-2024-23772

An issue was discovered in Quest KACE Agent for Windows 12.0.38 and 13.1.23.0. An Arbitrary file create vulnerability exists in the KSchedulerSvc.exe, KUserAlert.exe, and Runkbot.exe components. This allows local attackers to create any file of their choice with NT Authority\SYSTEM privileges.
Configurations

No configuration.

History

No history.

Information

Published : 2024-04-30 14:15

Updated : 2024-11-21 08:58


NVD link : CVE-2024-23772

Mitre link : CVE-2024-23772

CVE.ORG link : CVE-2024-23772


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')