CVE-2021-44028

MEDIUM

Quest KACE Desktop Authority 10.0-11.1 - XML External Entity Injection via log4net Configuration

Title source: llm
STIX 2.1

Description

XXE can occur in Quest KACE Desktop Authority before 11.2 because the log4net configuration file might be controlled by an attacker, a related issue to CVE-2018-1285.

Scores

CVSS v3 5.5
EPSS 0.0300
EPSS Percentile 85.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Details

CWE
CWE-611
Status published
Products (1)
quest/kace_desktop_authority 10.0 - 11.2
Published Dec 22, 2021
Tracked Since Feb 18, 2026