CVE-2024-23772
MEDIUMQuest KACE Agent for Windows <13.1.23.0 - File Create
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-23772. PoCs published by Verrideo.
AI-analyzed exploit summary The repository contains only a README.md with a placeholder title and no technical details or exploit code. It promises information 'in due course' but provides nothing substantive.
Description
An issue was discovered in Quest KACE Agent for Windows 12.0.38 and 13.1.23.0. An Arbitrary file create vulnerability exists in the KSchedulerSvc.exe, KUserAlert.exe, and Runkbot.exe components. This allows local attackers to create any file of their choice with NT Authority\SYSTEM privileges.
Exploits (1)
The repository contains only a README.md with a placeholder title and no technical details or exploit code. It promises information 'in due course' but provides nothing substantive.
References (2)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L