CVE-2025-32975
9.5 CISA KEVQuest · KACE Systems Management Appliance (SMA)
An authentication bypass vulnerability in the Quest KACE SMA SSO mechanism allows unauthenticated attackers to impersonate legitimate users and achieve administrative takeover.
Executive summary
A critical authentication bypass vulnerability in Quest KACE SMA is currently being exploited in the wild, posing an immediate risk of full administrative takeover.
Vulnerability
The vulnerability exists in the SSO authentication handling mechanism, allowing unauthenticated attackers to bypass security controls and impersonate any user, including administrative accounts.
Business impact
This vulnerability carries a CVSS score of 9.5, reflecting its critical severity. Successful exploitation allows an attacker to gain complete control over the KACE SMA, which manages critical enterprise assets. This could lead to massive data breaches, the deployment of malicious software across the managed network, and complete loss of system integrity.
Remediation
Immediate Action: Update the Quest KACE SMA to the specified patch versions: 13.0.385, 13.1.81, 13.2.183, 14.0.341 (Patch 5), or 14.1.101 (Patch 4).
Proactive Monitoring: Monitor server logs for unusual authentication patterns or unauthorized login attempts originating from unknown or suspicious IP addresses.
Compensating Controls: Restrict access to the KACE SMA management interface to trusted internal networks or VPNs to limit exposure to the public internet.
Exploitation status
Public Exploit Available: No (confirmed public weaponized exploit not available).
Analyst recommendation
Given the active exploitation and the critical nature of this flaw, immediate patching is mandatory for all exposed Quest KACE SMA instances. Organizations should treat this as a high priority incident and verify that all administrative accounts have not been compromised during the period of exposure.