CVE-2018-11132

CVE-2018-11132

In order to perform actions that require higher privileges, the Quest KACE System Management Appliance 8.0.318 relies on a message queue that runs daemonized with root privileges and only allows a set of commands to be executed. A command injection vulnerability exists within this message queue which allows low-privilege users to append arbitrary commands that will be run as root.

Source: CVE-2018-11132

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다