CVE-2024-23774

HIGH

Quest KACE Agent for Windows <13.1.23.0 - Code Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-23774. PoCs published by Verrideo.

AI-analyzed exploit summary The repository contains only a README with a placeholder message indicating future information about CVE-2024-23774, an unquoted Windows service path vulnerability. No exploit code or technical details are provided.

Description

An issue was discovered in Quest KACE Agent for Windows 12.0.38 and 13.1.23.0. An unquoted Windows search path vulnerability exists in the KSchedulerSvc.exe and AMPTools.exe components. This allows local attackers to execute code of their choice with NT Authority\SYSTEM privileges.

Exploits (1)

nomisec STUB
by Verrideo · poc
https://github.com/Verrideo/CVE-2024-23774

The repository contains only a README with a placeholder message indicating future information about CVE-2024-23774, an unquoted Windows service path vulnerability. No exploit code or technical details are provided.

Classification
Stub 95%
Attack Type
Lpe
Complexity
Trivial
Reliability
Theoretical
Target: Windows systems with vulnerable service configurations
Auth required
Prerequisites: Local access to the target system · Presence of a service with an unquoted path containing spaces
devstral-2 · analyzed Feb 19, 2026 Full analysis →

Scores

CVSS v3 7.8
EPSS 0.0044
EPSS Percentile 35.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-22
Status published
Published Apr 30, 2024
Tracked Since Feb 18, 2026