CVE-2024-23773

HIGH

Quest KACE Agent <13.1.23.0 - Privilege Escalation

Title source: llm
STIX 2.1

Description

An issue was discovered in Quest KACE Agent for Windows 12.0.38 and 13.1.23.0. An Arbitrary file delete vulnerability exists in the KSchedulerSvc.exe component. Local attackers can delete any file of their choice with NT Authority\SYSTEM privileges.

Exploits (1)

nomisec STUB
by Verrideo · poc
https://github.com/Verrideo/CVE-2024-23773

Scores

CVSS v3 7.8
EPSS 0.0033
EPSS Percentile 56.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-22
Status published
Published Apr 30, 2024
Tracked Since Feb 18, 2026