CVE-2024-23772

MEDIUM

Quest KACE Agent for Windows <13.1.23.0 - File Create

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-23772. PoCs published by Verrideo.

AI-analyzed exploit summary The repository contains only a README.md with a placeholder title and no technical details or exploit code. It promises information 'in due course' but provides nothing substantive.

Description

An issue was discovered in Quest KACE Agent for Windows 12.0.38 and 13.1.23.0. An Arbitrary file create vulnerability exists in the KSchedulerSvc.exe, KUserAlert.exe, and Runkbot.exe components. This allows local attackers to create any file of their choice with NT Authority\SYSTEM privileges.

Exploits (1)

nomisec STUB
by Verrideo · poc
https://github.com/Verrideo/CVE-2024-23772

The repository contains only a README.md with a placeholder title and no technical details or exploit code. It promises information 'in due course' but provides nothing substantive.

Classification
Stub 100%
Attack Type
Other
Complexity
Theoretical
Reliability
Theoretical
Target: unknown
No auth needed
devstral-2 · analyzed Feb 19, 2026 Full analysis →

Scores

CVSS v3 6.6
EPSS 0.0033
EPSS Percentile 24.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-22
Status published
Published Apr 30, 2024
Tracked Since Feb 18, 2026