|CVSS SCORE||9.0, (AV:N/AC:L/Au:S/C:C/I:C/A:C)|
KACE Systems Management
The specific flaw exists within the handling of the ID and FMT parameters provided to the run_report page. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to remotely execute code under the context of root.
Quest has issued an update to correct this vulnerability. More details can be found at:
This vulnerability is being disclosed publicly without a patch in accordance with the ZDI 120 day deadline.
04/20/18 - ZDI reported the vulnerabilities to the vendor