Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»Hackers Exploit CVE-2025-32975 (CVSS 10.0) to Hijack Unpatched Quest KACE SMA Systems
    Cybersecurity

    Hackers Exploit CVE-2025-32975 (CVSS 10.0) to Hijack Unpatched Quest KACE SMA Systems

    adminBy adminMarch 23, 2026No Comments2 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    Hackers Exploit CVE-2025-32975 (CVSS 10.0) to Hijack Unpatched Quest KACE SMA Systems
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananMar 23, 2026Vulnerability / Endpoint Security

    Threat actors are suspected to be exploiting a maximum-severity security flaw impacting Quest KACE Systems Management Appliance (SMA), according to Arctic Wolf.

    The cybersecurity company said it observed malicious activity starting the week of March 9, 2026, in customer environments that’s consistent with the exploitation of CVE-2025-32975 on unpatched SMA systems exposed to the internet. It’s currently not known what the end goals of the attack are.

    CVE-2025-32975 (CVSS score: 10.0) refers to an authentication bypass vulnerability that allows attackers to impersonate legitimate users without valid credentials. Successful exploitation of the flaw could facilitate the complete takeover of administrative accounts. The issue was patched by Quest in May 2025.

    In the malicious activity detected by Arctic Wolf, threat actors are believed to have weaponized the vulnerability to seize control of administrative accounts and execute remote commands to drop Base64-encoded payloads from an external server (216.126.225[.]156) via the curl command.

    The unknown attackers then proceeded to create additional administrative accounts via “runkbot.exe,” a background process associated with the SMA Agent that’s used to run scripts and manage installations. Also detected were Windows Registry modifications via a PowerShell script for possible persistence or system configuration changes.

    Other actions undertaken by the threat actors are listed below –

    • Conducting credential harvesting using Mimikatz.
    • Performing discovery and reconnaissance by enumerating logged-in users and administrator accounts, and running “net time” and “net group” commands.
    • Obtaining remote desktop protocol (RDP) access to backup infrastructure (Veeam, Veritas) and domain controllers.

    To counter the threat, administrators are advised to apply the latest updates and avoid exposing SMA instances to the internet. The issue has been addressed in versions 13.0.385, 13.1.81, 13.2.183, 14.0.341 (Patch 5), and 14.1.101 (Patch 4).

    CVE202532975 CVSS exploit hackers Hijack KACE Quest SMA Systems Unpatched
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleYour AI agents are moving sensitive data. Do you know where?
    Next Article After the Galaxy S26 Ultra, Samsung may finally speed up charging on its foldables
    admin
    • Website

    Related Posts

    The Open Standard That Gives AI Systems A Structured View Of Your Business

    June 1, 2026

    Encryption Consulting launches CertSecure Manager v3.3 with zero-touch certificate renewals

    May 20, 2026

    GitHub confirms breach of 3,800 repos via malicious VSCode extension

    May 20, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    The 50 Most-Cited Websites in Copilot (June 2026)

    June 2, 2026

    What Google’s New AI Guide Actually Debunks. And What It Doesn’t

    June 2, 2026

    Broadcom, Samsung team for wireless SoC

    June 2, 2026

    What it means for your marketing strategy in 2026

    June 1, 2026
    Categories
    • Blogging (88)
    • Cybersecurity (1,955)
    • Privacy & Online Earning (230)
    • SEO & Digital Marketing (1,332)
    • Tech Tools & Mobile / Apps (1,796)
    • WiFi / Internet & Networking (322)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    The 50 Most-Cited Websites in Copilot (June 2026)

    June 2, 2026

    What Google’s New AI Guide Actually Debunks. And What It Doesn’t

    June 2, 2026

    Broadcom, Samsung team for wireless SoC

    June 2, 2026
    Most Popular
    • The 50 Most-Cited Websites in Copilot (June 2026)
    • What Google’s New AI Guide Actually Debunks. And What It Doesn’t
    • Broadcom, Samsung team for wireless SoC
    • What it means for your marketing strategy in 2026
    • DV360 API Adds Demand Gen Support
    • The 50 Most-Cited Websites in Grok (June 2026)
    • Can Chinese memory maker CXMT help relieve the memory shortage?
    • Google CEO Sundar Pichai Downplays Google Zero Concerns
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.