Skip to main content

Vendor/product archive

quest / kace_desktop_authority CVEs

Beta · best-effort

5 CVEs tagged to quest / kace_desktop_authority2 Critical, 0 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2021-44031

Published Dec 22, 2021

An issue was discovered in Quest KACE Desktop Authority before 11.2. /dacomponentui/profiles/profileitems/outlooksettings/Insertimage.aspx contains a vulnerability that could allo…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-44030

Published Dec 22, 2021

Quest KACE Desktop Authority before 11.2 allows XSS because it does not prevent untrusted HTML from reaching the jQuery.htmlPrefilter method of jQuery.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-44029

Published Dec 22, 2021

An issue was discovered in Quest KACE Desktop Authority before 11.2. This vulnerability allows attackers to execute remote code through a deserialization exploitation in the RadAs…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-44028

Published Dec 22, 2021

XXE can occur in Quest KACE Desktop Authority before 11.2 because the log4net configuration file might be controlled by an attacker, a related issue to CVE-2018-1285.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1