Hackers Exploit CVE-2025-32975 (CVSS 10.0) to Hijack Unpatched Quest KACE SMA Systems
好的,我现在需要帮用户总结这篇文章的内容,控制在100字以内。首先,我得仔细阅读文章,理解其主要内容。 文章讲的是Arctic Wolf发现网络攻击者利用Quest KACE SMA的一个严重漏洞CVE-2025-32975进行攻击。这个漏洞的CVSS评分是10.0,属于最高级别。攻击者通过这个漏洞绕过认证,接管管理员账户,并执行远程命令,投放恶意软件。此外,他们还创建了新的管理员账户,并修改了Windows注册表以维持持久性。 接下来,攻击者进行了凭证窃取、侦察活动,并获得了对备份基础设施和域控制器的远程访问权限。文章建议管理员安装补丁并避免将SMA暴露在互联网上。 现在,我需要将这些信息浓缩到100字以内。重点包括:漏洞名称、CVSS评分、攻击手段、影响以及防御建议。 确保语言简洁明了,不使用复杂的术语,让读者一目了然。同时,避免使用“这篇文章总结”之类的开头语,直接进入内容。 最后检查字数是否符合要求,并确保信息准确无误。 </think> 网络攻击者利用Quest KACE SMA的高危漏洞CVE-2025-32975(CVSS 10.0)绕过认证并接管管理员账户。通过curl命令从外部服务器投放Base64编码载荷,并创建新管理员账户及修改注册表以维持持久性。攻击者还窃取凭证、侦察系统并获取对备份基础设施和域控制器的远程访问权限。建议管理员安装补丁并避免将SMA暴露于互联网。 2026-3-23 06:15:0 Author: thehackernews.com(查看原文) 阅读量:10 收藏

Vulnerability / Endpoint Security

Threat actors are suspected to be exploiting a maximum-severity security flaw impacting Quest KACE Systems Management Appliance (SMA), according to Arctic Wolf.

The cybersecurity company said it observed malicious activity starting the week of March 9, 2026, in customer environments that's consistent with the exploitation of CVE-2025-32975 on unpatched SMA systems exposed to the internet. It's currently not known what the end goals of the attack are.

CVE-2025-32975 (CVSS score: 10.0) refers to an authentication bypass vulnerability that allows attackers to impersonate legitimate users without valid credentials. Successful exploitation of the flaw could facilitate the complete takeover of administrative accounts. The issue was patched by Quest in May 2025.

In the malicious activity detected by Arctic Wolf, threat actors are believed to have weaponized the vulnerability to seize control of administrative accounts and execute remote commands to drop Base64-encoded payloads from an external server (216.126.225[.]156) via the curl command.

The unknown attackers then proceeded to create additional administrative accounts via "runkbot.exe," a background process associated with the SMA Agent that's used to run scripts and manage installations. Also detected were Windows Registry modifications via a PowerShell script for possible persistence or system configuration changes.

Other actions undertaken by the threat actors are listed below -

  • Conducting credential harvesting using Mimikatz.
  • Performing discovery and reconnaissance by enumerating logged-in users and administrator accounts, and running "net time" and "net group" commands.
  • Obtaining remote desktop protocol (RDP) access to backup infrastructure (Veeam, Veritas) and domain controllers.

To counter the threat, administrators are advised to apply the latest updates and avoid exposing SMA instances to the internet. The issue has been addressed in versions 13.0.385, 13.1.81, 13.2.183, 14.0.341 (Patch 5), and 14.1.101 (Patch 4).

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.


文章来源: https://thehackernews.com/2026/03/hackers-exploit-cve-2025-32975-cvss-100.html
如有侵权请联系:admin#unsafe.sh