Skip to content
COOEY

FAIL › dossier

Quest

VENDOR

· dossier confidence 20%

Quest is an IT infrastructure vendor whose KACE appliances have suffered multiple critical vulnerabilities, including remote code execution and authentication bypass flaws that were actively exploited by ransomware groups. The company's track record shows a pattern of unpatched edge-device vulnerabilities that pose significant risk to enterprise environments.

PROFILE
CategoryIT infrastructure / endpoint managementWhat they doQuest provides enterprise IT management solutions including KACE appliances for asset and systems management. Websitehttps://www.quest.com ↗
SECURITY POSTURE

Quest has a documented history of critical vulnerabilities in its KACE appliances, including remote code execution and authentication bypass flaws that were actively exploited by ransomware groups.

Notable failures
  • CVE-2018-11138 RCE in KACE appliances exploited by ransomware
  • CVE-2025-32975 authentication bypass in KACE SMA
  • Unpatched public script allowing anonymous RCE
Patterns: repeated unpatched edge-device RCEs; authentication bypass in management appliances
Reputationsevere-fallout (-0.60) · 1 trusted sources Coveragecooey
FAILURE HISTORY · 3
DATEEVENTSEVSUMMARY
2022-03-25 CVE-2018-11138 critical A publicly accessible script in Quest KACE appliances allowed anonymous users to execute arbitrary code remotely, actively exploited by ransomware groups.
2026-04-20 CVE-2025-32975 high Quest KACE SMA allows impersonation without credentials, enabling attackers to bypass authentication controls.
2018-05-31 CVE-2018-11138 critical CVE-2018-11138: The '/common/download_agent_installer.php' script in the Quest KACE System Manag
SENTIMENT · TRUSTED SOURCES
synthesissevere-fallout-0.60
Quest's vulnerability allowed arbitrary command execution via an accessible script, representing a critical security failure with severe fallout for enterprise environments relying on KACE appliances.
cooey ↗severe-fallout-0.60
Critical vulnerability allowing arbitrary command execution via an accessible script, representing a severe security failure for enterprise environments.
"The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users and can be abused to execute arbitrary commands on the system."
Open questions: Quest's current patch management SLA for KACE appliances · Whether Quest has implemented zero-trust access controls for KACE management interfaces
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-24 03:46:15.161680+00:00