← Vulnerability feed

Vulnerability record · CVE-2018-11138 · published 31 May 2018

CVE-2018-11138: Quest KACE System Management Appliance unauthenticated OS command injection

Quest · Kace System Management Appliance

The download_agent_installer.php script in Quest KACE System Management Appliance 8.0.318 is reachable by anonymous users and passes input to the operating system without proper sanitization, allowing arbitrary command execution. Because no authentication is required, any network-reachable attacker can run commands as the web service account on the appliance.

9.8 CVSS 3.1 Critical CISA KEV since 25 Mar 2022 Known ransomware use EPSS 92% · top 0.2% CWE-78 · OS command injection
9.8CVSS 3.1 base score, v2 10.0
92%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
5References, 4 tagged exploit
13 Aug 2026Last modified by NVD

Description

The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users and can be abused to execute arbitrary commands on the system.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityUnauthenticated remote command execution with a CVSS score of 9.8, active exploitation in CISA KEV, and documented ransomware use make this an urgent patch-first issue.

What it is

The download_agent_installer.php script in Quest KACE System Management Appliance 8.0.318 is reachable by anonymous users and passes input to the operating system without proper sanitization, allowing arbitrary command execution. Because no authentication is required, any network-reachable attacker can run commands as the web service account on the appliance.

Impact

An attacker gains remote code execution on the KACE appliance, enabling full compromise of the system and any credentials or managed endpoints it controls. CISA lists this vulnerability as used in known ransomware campaigns, so impact can extend to enterprise-wide encryption and lateral movement.

Attack surface

Reached over the network via HTTP(S) requests to /common/download_agent_installer.php; the CVSS vector shows PR:N and UI:N, meaning no authentication and no user interaction are required.

Exploitation

CISA KEV lists it as actively exploited with known ransomware campaign use, and EPSS is 0.92061 (99.8th percentile); public exploit code is referenced in Exploit-DB and Core Security advisories.

What to do

  • Apply the vendor update for KACE System Management Appliance per Quest instructions; this is the only complete fix.
  • If patching cannot be done immediately, restrict network access to the appliance management interface to trusted administrative networks only.
  • Block or monitor external access to /common/download_agent_installer.php at the perimeter until the patch is applied.
  • Rotate credentials and secrets stored on or managed by the appliance after any suspected exposure.
  • Review appliance logs for unauthorized command execution or unexpected outbound connections.

Detection

  • Monitor web server and appliance logs for requests to /common/download_agent_installer.php, especially with unusual parameters or command metacharacters.
  • Alert on unexpected child processes spawned by the web service account (for example shell, curl, wget, or netcat).
  • Hunt for outbound connections from the KACE appliance to unfamiliar hosts or command-and-control infrastructure.
  • Correlate appliance access with authentication logs to identify anonymous access to administrative scripts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2018-11138 to the Known Exploited Vulnerabilities catalog on 25 March 2022 as "Quest KACE System Management Appliance Remote Command Execution Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 15 April 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-11138 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-11136Quest kace system management appliance sql injection vulnerabilityThe 'orgID' parameter received by the '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is not sani…EPSS 1.4%9.8CVE-2018-11140Quest kace system management appliance sql injection vulnerabilityThe 'reportID' parameter received by the '/common/run_report.php' script in the Quest KACE System Management Appliance 8.0.318 is not sanitized, lead…EPSS 1.4%9.8CVE-2018-11141Quest kace system management appliance path traversal vulnerabilityThe 'IMAGES_JSON' and 'attachments_to_remove[]' parameters of the '/adminui/advisory.php' script in the Quest KACE System Management Virtual Applianc…EPSS 2.0%8.8CVE-2018-11132Quest kace system management appliance os command injection vulnerabilityIn order to perform actions that require higher privileges, the Quest KACE System Management Appliance 8.0.318 relies on a message queue that runs da…EPSS 18%8.8CVE-2018-11134Quest kace system management appliance weak password recovery vulnerabilityIn order to perform actions that requires higher privileges, the Quest KACE System Management Appliance 8.0.318 relies on a message queue managed tha…EPSS 3.0%8.8CVE-2018-11135Quest kace system management appliance prototype pollution vulnerabilityThe script '/adminui/error_details.php' in the Quest KACE System Management Appliance 8.0.318 allows authenticated users to conduct PHP object inject…EPSS 2.1%8.8CVE-2018-11139Quest kace system management appliance os command injection vulnerabilityThe '/common/ajax_email_connection_test.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by any authenticated user and…EPSS 43%6.5CVE-2018-11137Quest kace system management appliance path traversal vulnerabilityThe 'checksum' parameter of the '/common/download_attachment.php' script in the Quest KACE System Management Appliance 8.0.318 can be abused to read …EPSS 6.5%

Source: NIST National Vulnerability Database (record CVE-2018-11138), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.