An issue was discovered in Quest KACE Agent for Windows 12.0.38 and 13.1.23.0. An Arbitrary file delete vulnerability exists in the KSchedulerSvc.exe component. Local attackers can delete any file of their choice with NT Authority\SYSTEM privileges.
History

Thu, 26 Feb 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Quest
Quest kace Systems Management Appliance
CPEs cpe:2.3:a:quest:kace_systems_management_appliance:*:*:*:*:*:*:*:*
Vendors & Products Quest
Quest kace Systems Management Appliance
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-04-30T00:00:00.000Z

Updated: 2024-08-01T23:13:07.566Z

Reserved: 2024-01-22T00:00:00.000Z

Link: CVE-2024-23773

cve-icon Vulnrichment

Updated: 2024-08-01T23:13:07.566Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-04-30T14:15:15.040

Modified: 2024-11-21T08:58:22.803

Link: CVE-2024-23773

cve-icon Redhat

No data.