Hackers Exploit Quest KACE SMA Flaw to Harvest Credentials
Security Researchers have detected active exploitation targeting unpatched Quest KACE Systems Management Appliance (SMA) instances.
Security Researchers have detected active exploitation targeting unpatched Quest KACE Systems Management Appliance (SMA) instances.
Starting the week of Mar 9, 2026, threat actors began leveraging a critical authentication bypass vulnerability , identified as CVE-2025-32975, to infiltrate corporate networks, harvest sensitive credentials, and pivot toward critical infrastructure.
Quest KACE SMA is a popular on-premises solution designed for centralized endpoint management, handling tasks ranging from software deployment to endpoint monitoring.
CVE-2025-32975 represents a severe flaw within the appliance’s Single Sign-On (SSO) authentication handling mechanism.
By exploiting this vulnerability, attackers can successfully bypass authentication protocols and impersonate legitimate users without needing valid credentials.
This effectively grants them complete administrative takeover of the appliance. Although Quest originally released a patch for this flaw in May 2025 alongside several other related vulnerabilities, publicly exposed and outdated systems remain highly vulnerable to compromise nearly a year later.
Security researchers at Arctic Wolf discovered that, upon gaining initial access through the SSO bypass, attackers move rapidly to establish a firm foothold in the victim's environment.
They leverage the native KPluginRunProcess functionality within the KACE software to execute remote commands, heavily relying on Base64-encoded payloads to evade immediate security detection.
Security Researchers have detected active exploitation targeting unpatched Quest KACE Systems Management Appliance (SMA) instances.
Researchers observed the attackers using simple curl commands to download additional malicious files from an external command-and-control server located at the IP address 216.126.225.156.
To maintain stealthy persistence, the threat actors abuse the legitimate runkbot.exe process to spawn unauthorized administrative accounts .
They actively attempt to add rogue users to both local and domain administrator groups to solidify their network control.
Furthermore, the attackers deploy hidden PowerShell scripts, such as Enable-UpdateServices.ps1 and taskband.ps1, to silently modify registry settings and ensure their backdoor access survives system reboots and routine maintenance.
Once entrenched, the operation shifts entirely to credential access and internal discovery.
The attackers deploy the notorious Mimikatz tool, sometimes cleverly disguised under the arbitrary filename asd.exe, to harvest plaintext credentials directly from memory.
They then aggressively map the local environment and domain administrative structures using native enumeration commands.
Armed with fresh credentials and network maps, the adversaries pivot laterally through the network.
Most alarmingly, researchers noted attackers establishing Remote Desktop Protocol (RDP) sessions to critical infrastructure elements, including domain controllers and enterprise backup servers running Veeam or Veritas software.
To prevent exploitation, administrators must immediately upgrade their KACE SMA environments to the latest patched releases.
Users operating on older 13.0, 13.1, and 13.2 branches must upgrade to versions 13.0.385, 13.1.81, and 13.2.183 or later, respectively.
Similarly, environments running the newer 14.0 and 14.1 branches must apply Patch 5 (version 14.0.341) and Patch 4 (version 14.1.101) to secure their systems.
Additionally, organisations should proactively remove any KACE SMA interfaces from the public internet, restricting remote administrative access strictly to secure VPNs or enterprise firewalls to minimise their external attack surface.
Based on reporting by GBHackers.
