Vulnerability record · CVE-2025-32975 · published 24 June 2025
CVE-2025-32975: Quest KACE SMA SSO authentication bypass allows admin takeover
Quest · Kace Systems Management Appliance
Quest KACE Systems Management Appliance contains an authentication bypass in its SSO authentication handling, letting attackers impersonate legitimate users without valid credentials. Because the appliance is used for endpoint management and patching, a bypass leading to full administrative takeover puts every managed device at risk.
Description
Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch 4) contains an authentication bypass vulnerability that allows attackers to impersonate legitimate users without valid credentials. The vulnerability exists in the SSO authentication handling mechanism and can lead to complete administrative takeover.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 10.0 unauthenticated network authentication bypass leading to full administrative takeover, with confirmed exploitation per CISA KEV.
What it is
Quest KACE Systems Management Appliance contains an authentication bypass in its SSO authentication handling, letting attackers impersonate legitimate users without valid credentials. Because the appliance is used for endpoint management and patching, a bypass leading to full administrative takeover puts every managed device at risk.
Impact
An unauthenticated attacker can impersonate users and achieve complete administrative control of the KACE SMA, enabling management-agent abuse, script or patch deployment, and access to managed endpoints and their data.
Attack surface
Reachable over the network via the SSO authentication handling mechanism, per the CVSS vector AV:N/AC:L/PR:N/UI:N, so no authentication or user interaction is required. The description does not specify which SSO endpoint or protocol is involved.
Exploitation
CVE-2025-32975 is listed in CISA KEV with a 2026-05-04 remediation due date, indicating known exploitation; EPSS 30-day probability is about 2.5 percent (83rd percentile). No ransomware campaign use is documented.
What to do
- Upgrade to the fixed KACE SMA releases: 13.0.385, 13.1.81, 13.2.183, 14.0.341 (Patch 5) or 14.1.101 (Patch 4), or later.
- If patching is not immediately possible, follow the vendor's KB 4379499 mitigation guidance or restrict/disable SSO authentication until the appliance is updated.
- Remove KACE SMA management interfaces from direct internet exposure; place them behind VPN or an access-controlled reverse proxy.
- Audit and rotate credentials and API keys used by the appliance, and review local and SSO-linked accounts for unauthorized additions.
- Apply CISA KEV required actions and BOD 22-01 guidance, including discontinuing use if mitigations are unavailable.
Detection
- Review KACE SMA authentication and SSO logs for successful logins without a preceding credential or SSO assertion, and for logins from unexpected source IPs or user agents.
- Monitor for new or modified administrative accounts, role changes, and unexpected script, patch or agent deployment tasks on the appliance.
- Alert on outbound connections from the SMA to unusual destinations, which may indicate post-exploitation activity.
- Correlate appliance audit logs with downstream endpoint management actions to spot unauthorized mass deployment or configuration changes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-32975 to the Known Exploited Vulnerabilities catalog on 20 April 2026 as "Quest KACE Systems Management Appliance (SMA) Improper Authentication Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 4 May 2026.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://seclists.org/fulldisclosure/2025/Jun/22 | Mailing ListThird Party Advisory |
| https://seralys.com/research/CVE-2025-32975.txt | Third Party Advisory |
| https://support.quest.com/kb/4379499/quest-response-to-kace-sma-vulnerabilities-cve-2025-32975-cve-2025-32976-cve-2025-3 | Vendor Advisory |
| http://seclists.org/fulldisclosure/2025/Jun/25 | Mailing ListThird Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-32975 | US Government Resource |
Track CVE-2025-32975 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-32975), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.