HomeSecurityQuest KACE SMA: Hackers exploit critical vulnerability

Quest KACE SMA: Hackers exploit a critical vulnerability

The vulnerability , CVE-2025-32975, with a CVSS score of 10.0, is the target of active attacks by cybercriminals exploiting unpatched Quest KACE Systems Management Appliance (SMA). According to cybersecurity firm Arctic Wolf, the malicious activity was first detected the week of March 9, 2026 in customer environments with SMA systemsexposed to the internet without the necessary security updates.

Quest KACE

CVE -2025-32975 is an authentication bypass vulnerability that allows attackers to impersonate legitimate users without valid credentials. Successful exploitation of this vulnerability could lead to full administrative account takeover, giving attackers unrestricted access to the system. Quest released a patch for the vulnerability in May 2025, however many systems remain vulnerable.

See also: Hackers exploit Langflow vulnerability

Arctic Wolf researchers have identified that attackers are exploiting CVE-2025-32975 to gain control of administrative accounts and execute remote commands. Specifically, cybercriminals download encrypted payloads from an external server (with IP address 216.126.225.156 ) using the curl command . This tactic allows malware to be installed and gain a presence on the targeted system.

After initial penetration, the attackers proceed to create additional administrative accounts via runkbot.exe, a background process associated with the SMA Agent used to execute scripts and manage installations. In addition, modifications to the Windows Registry via PowerShell scripts were detected, which are likely aimed at maintaining their presence or making system configuration changes.

See also: Hackers Target Uyghurs and Tibetans with MOONSHINE Exploit and DarkNimbus Backdoor

Article image: CISA Flags Actively Exploited Wing FTP Vulnerability Leaking Server Paths - illustration 2

Quest KACE SMA – CVE-2025-32975: Attack Methods

The cyberattacks observed include extensive reconnaissance and credential harvesting activities . Attackers use the Mimikatz tool to extract passwords from system memory, while also executing commands such as net time and net group to enumerate logged-in users and administrative accounts. In addition, they gain access via Remote Desktop Protocol (RDP) to critical backup infrastructure such as Veeam and Veritas , as well as domain controllers.

Protection Recommendations

Quest KACE SMA is widely used for endpoint management, system inventory, patching, and network monitoring in thousands of organizations worldwide.

See also: Telus Digital breach – Hackers say they stole 1PB of data

Quest KACE SMA: Hackers exploit a critical vulnerability

To protect against these attacks, administrators should immediately apply the available security updates. Specifically, they should update their systems to SMA versions 13.0.385, 13.1.81, 13.2.183, 14.0.341 (Patch 5), or 14.1.101 (Patch 4) via Admin > Settings > Appliance Updates. Users of versions 13.x should download the hotfix from the Quest.

Additionally, it is recommended to isolate SMA systems from direct internet exposure and continuously monitor logs for suspicious activity. Administrators should look for clues such as Base64 payloads, KPluginRunProcess or runkbot.exe activity , and check for unauthorized account creation. Finally, they should scan for connections to the IP address 216.126.225.156 used as a command and control server by the attackers (according to The Hacker News).

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS