Skip to content
COOEY

FAIL › dossier

KACE System Management Appliance

PRODUCT

· dossier confidence 20%

KACE System Management Appliance is an IT management solution from Quest Software that suffered a critical RCE vulnerability actively exploited by ransomware groups, highlighting a severe historical security weakness in its publicly accessible scripts.

PROFILE
CategoryIT Management SoftwareWhat they doKACE System Management Appliance is an IT management and endpoint management solution provided by Quest Software. Websitehttps://support.quest.com/kace-systems-management-appliance/15.0/ ↗
SECURITY POSTURE

The product has a critical remote code execution vulnerability that was actively exploited by ransomware groups, indicating a significant historical security weakness.

Notable failures
  • CVE-2018-11138 RCE exploited by ransomware
Patterns: critical unpatched RCE in publicly accessible scripts
FAILURE HISTORY · 2
DATEEVENTSEVSUMMARY
2022-03-25 CVE-2018-11138 critical A publicly accessible script in Quest KACE appliances allowed anonymous users to execute arbitrary code remotely, actively exploited by ransomware groups.
2018-05-31 CVE-2018-11138 critical CVE-2018-11138: The '/common/download_agent_installer.php' script in the Quest KACE System Manag
Open questions: Quest Software's current acquisition status and KACE's product line evolution post-2018
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-24 03:47:13.142618+00:00