In order to perform actions that requires higher privileges, the Quest KACE System Management Appliance 8.0.318 relies on a message queue…
mitre·CWE-640·Published 2018-05-31
In order to perform actions that requires higher privileges, the Quest KACE System Management Appliance 8.0.318 relies on a message queue managed that runs with root privileges and only allows a set of commands. One of the available commands allows changing any user's password (including root). A low-privilege user could abuse this feature by changing the password of the 'kace_support' account, which comes disabled by default but has full sudo privileges.
In order to perform actions that requires higher privileges, the Quest KACE System Management Appliance 8.0.318 relies on a message queue managed that runs with root privileges and only allows a set of commands. One of the available commands allows changing any user's password (including root). A low-privilege user could abuse this feature by changing the password of the 'kace_support' account, which comes disabled by default but has full sudo privileges.
Para realizar acciones que requieran mayores privilegios, Quest KACE System Management Appliance 8.0.318 se basa en una cola de mensajes gestionada que se ejecuta con privilegios root y sólo permite un conjunto de comandos. Uno de los comandos disponibles permite cambiar la contraseña de cualquier usuario (incluyendo root). Un usuario de bajos privilegios podría explotar esta característica cambiando la contraseña de la cuenta "kace_support", que viene desactivada por defecto pero tiene todos los privilegios de sudo.
| Version | Type | Source | Base | Exp | Impact | Vector |
|---|---|---|---|---|---|---|
| 2.0 | Primary | NVD | 9.0 | 8.0 | 10.0 | AV:N/AC:L/Au:S/C:C/I:C/A:C |
| 3.0 | Primary | NVD | 8.8 | 2.8 | 5.9 | CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |