CVE-2025-32975
Quest KACE Systems Management Appliance (SMA) Improper Authentication Vulnerability
Description
CVE-2025-32975 is a critical improper authentication vulnerability in Quest KACE Systems Management Appliance (SMA), a widely deployed enterprise endpoint management and software deployment platform used by IT teams to manage, patch, and provision devices at scale. The vulnerability allows unauthenticated remote attackers to impersonate legitimate users without presenting valid credentials, effectively bypassing the entire authentication layer of the KACE SMA web interface. In enterprise environments, KACE SMA typically holds administrative access to thousands of endpoints, software package repositories, and agent-managed devices — meaning a successful authentication bypass grants attackers the ability to perform administrative functions across the entire managed device fleet. CISA added CVE-2025-32975 to the Known Exploited Vulnerabilities (KEV) catalog on 2026-04-20, with a remediation due date of 2026-05-04, indicating confirmed active exploitation in the wild. The EPSS score is 0.42123, placing this vulnerability in the 97.5th percentile of all CVEs — meaning it is being attempted at a significantly higher rate than 97.5% of known vulnerabilities, making it an extremely high exploitation-priority target. No ransomware campaigns have been specifically named in association with this CVE, though the administrative access it provides to endpoint management infrastructure is a known enabler of ransomware pre-positioning activities.
KEV Information
CVSS Score
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HOpen in CalculatorAffected Products
| Vendor | Product | Version |
|---|---|---|
| quest | kace systems management appliance | >= 13.0, < 13.0.385; >= 13.1, < 13.1.81; >= 13.2, < 13.2.183; >= 14.0, < 14.0.341; >= 14.1, < 14.1.101 |
References
- https://seclists.org/fulldisclosure/2025/Jun/22(Mailing List, Third Party Advisory)
- https://seralys.com/research/CVE-2025-32975.txt(Third Party Advisory)
- https://support.quest.com/kb/4379499/quest-response-to-kace-sma-vulnerabilities-cve-2025-32975-cve-2025-32976-cve-2025-32977-cve-2025-32978(Vendor Advisory)
- http://seclists.org/fulldisclosure/2025/Jun/25(Mailing List, Third Party Advisory)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-32975(US Government Resource)
Weakness Type
CWE-287: Improper Authentication
CWE-287 describes a class of vulnerabilities where a system either fails to prove that a user is who they claim to be, or implements the proof mechanism in a way that can be bypassed by an attacker. In the context of CVE-2025-32975, Quest KACE SMA's authentication mechanism contains a flaw that allows an attacker to craft requests that the system accepts as authenticated for a legitimate user's session without that user's credentials ever being verified. This may manifest as a flawed session token validation routine, a logic error in the authentication state machine, a bypassable cookie or header check, or an endpoint that incorrectly assumes authentication has occurred based on the presence of a user identifier parameter.
Improper authentication in enterprise management platforms is particularly devastating because these systems are designed to be trusted anchors for device management operations. The assumption baked into KACE SMA's design — that any authenticated request comes from a verified user — is violated by this vulnerability, collapsing the entire privilege model. An attacker who successfully impersonates a KACE administrator can execute software deployments, run scripted tasks on managed endpoints, access hardware and software inventory data, harvest credentials stored in KACE's managed credential store, and modify agent configurations — all without ever knowing the legitimate user's password. The impersonation is not merely read access; it grants full operational authority within the scope of the impersonated account.
Learn more: CWE-287 — Improper Authentication
Impact Analysis
The attack vector is Network, meaning no physical or local access is required — an internet-connected or internally reachable KACE SMA instance is sufficient. Attack Complexity is Low, as the vulnerability does not require special preconditions, race conditions, or knowledge of non-public information beyond identifying the target. Privileges Required is None — this is a pre-authentication vulnerability, exploitable by any unauthenticated attacker who can reach the KACE SMA web interface. User Interaction is None — no action by a legitimate user is needed to trigger the vulnerability. The scope does not change at the CVSS layer, but in practice the operational blast radius extends well beyond the KACE SMA appliance itself to every managed endpoint in the fleet.
Confidentiality impact is High: an attacker gains access to complete hardware and software inventory across all managed devices, stored credentials in KACE's managed credentials feature, software license information, user account mappings, and potentially domain credentials used for software deployments or agent communication. Integrity impact is High: the attacker can deploy arbitrary software packages to managed endpoints, execute scripts via KACE's scripting engine across the device fleet, modify patch management policies to prevent security updates, and alter agent configurations. Availability impact is High: the attacker can trigger device wipes, uninstall critical software, disrupt patch deployment schedules, or use KACE as a distribution point for destructive payloads. Given the 97.5th percentile EPSS score and confirmed KEV listing, organizations should prioritize this as a critical incident-response-level remediation, not a routine patching cycle item.
Exploit Maturity
CVE-2025-32975 is confirmed as actively exploited in the wild, with CISA adding it to the KEV catalog on 2026-04-20 and setting a remediation deadline of 2026-05-04 under Binding Operational Directive 22-01. The KEV listing is corroborated by an EPSS score of 0.42123 — the 97.5th percentile — which is a remarkably high exploitation probability score, placing this vulnerability in the top 2.5% of all CVEs by observed exploitation frequency. The EPSS score reflects actual exploitation telemetry from honeypots, IDS sensors, and threat intelligence feeds, meaning active exploit attempts have been observed at significant scale.
No specific named ransomware groups or APT actors have been publicly attributed to exploitation of CVE-2025-32975 at time of publication. However, the capability it provides — unauthenticated access to enterprise endpoint management infrastructure — is a canonical enabler for both financially motivated ransomware operators and espionage actors. Ransomware groups frequently target RMM (Remote Monitoring and Management) and MDM (Mobile Device Management) platforms because they provide built-in mechanisms for mass software deployment, making them effective ransomware distribution channels once compromised. The administrative access to managed endpoints that KACE SMA provides maps precisely to the "living off the land" tooling that modern ransomware operators prefer.
The combination of very high EPSS score and KEV confirmation makes CVE-2025-32975 a critical immediate remediation priority for all organizations running Quest KACE SMA, regardless of whether they have yet observed indicators of compromise.
Remediation
-
CISA KEV Directive Compliance: Federal civilian executive branch agencies must remediate CVE-2025-32975 by 2026-05-04 per the CISA KEV binding operational directive (BOD 22-01). All other organizations should apply the same deadline as a best practice given the 97.5th percentile EPSS score indicating mass exploitation attempts.
-
Apply Quest KACE SMA Patch: Update Quest KACE Systems Management Appliance to the version that resolves CVE-2025-32975, as specified in Quest's security advisory. Quest KACE SMA updates are applied through the Administrator Console under Settings > General Settings > Quest KACE SMA Update or via the appliance's built-in update mechanism. Verify the current version and consult Quest's advisory for the minimum fixed release.
-
Interim Mitigations: If patching cannot be completed immediately, restrict network access to the KACE SMA web interface (typically port 443) to only trusted internal management network ranges using firewall ACLs or network security groups. Disable all external internet exposure of the KACE SMA admin interface immediately. Consider placing the appliance in a maintenance mode that blocks new connections if network restriction is not feasible.
-
Network and Access Controls: Audit current network exposure of the KACE SMA appliance — confirm it is not reachable from the internet, guest networks, or untrusted VLANs. Enforce network segmentation so that KACE SMA is only reachable from administrator workstations and managed device subnets required for agent communication. If remote management is needed, require VPN with MFA before KACE SMA is reachable.
-
Detection and Incident Investigation: Review KACE SMA access logs for any authentication events that do not correspond to known administrator activity, particularly from unexpected IP addresses. Examine KACE SMA audit logs for unusual scripted task executions, software deployments, or configuration changes — especially during off-business hours. Search for any new accounts created in KACE SMA or changes to administrator group membership. Given the KEV confirmation, assume any unexplained KACE SMA activity since the CVE's public disclosure may represent an active compromise.
-
Defense-in-Depth for CWE-287: Implement network-level authentication (VPN with MFA) as a prerequisite to reaching any management appliance interface. Enforce session token validation server-side for all KACE SMA API and web requests. Review and rotate all credentials stored in KACE SMA's managed credentials feature if any unauthorized access is suspected. Enable and forward KACE SMA audit logs to a SIEM for ongoing monitoring of authentication anomalies.
Technical Details
CVE-2025-32975 is classified under CWE-287 (Improper Authentication), indicating that the root cause lies in the authentication verification logic of the Quest KACE SMA web application layer. Quest KACE SMA is built as a web-based appliance management platform, and its authentication system governs access to the administrator console and underlying API endpoints that control endpoint management operations.
The vulnerability allows an attacker to impersonate legitimate users — including administrators — without supplying valid credentials. This type of authentication bypass can arise from multiple root causes: session fixation or forged session token acceptance, logic errors in the authentication middleware that allow requests to bypass credential checks if certain parameters are present, insecure direct object references that allow user context to be set without authentication, or flaws in the SAML/SSO integration logic if external authentication is configured. The specific technical mechanism is detailed in Quest's vendor advisory.
The high EPSS score (0.42123, 97.5th percentile) indicates that this vulnerability has been observed in widespread exploitation attempts in the wild, consistent with the KEV listing. Quest KACE SMA is deployed across a broad range of enterprise environments, including healthcare, education, government, and financial services, providing threat actors with a high-value, high-availability target surface. The appliance typically runs with elevated trust relationships to managed endpoints via the KACE agent, meaning successful authentication bypass provides not just KACE console access but a trusted software distribution channel to all managed devices.
Quest's security advisory (available on the Quest Support Portal) provides the fixed version information, CVSSv3 vector, and any additional technical indicators. Organizations should consult the advisory for environment-specific remediation guidance, as SMA deployment configurations (virtual appliance vs. physical, HA configurations, agent connectivity) may affect patch application procedures.
Frequently Asked Questions
Is CVE-2025-32975 being actively exploited?
Yes. CISA confirmed active exploitation by adding CVE-2025-32975 to the KEV catalog on 2026-04-20. This is further supported by an EPSS score of 0.42123 (97.5th percentile), which reflects observed exploitation attempts at very high frequency in threat intelligence telemetry. Organizations should treat this as an active exploitation event and prioritize remediation accordingly.
What products are affected?
Quest KACE Systems Management Appliance (SMA) is affected. KACE SMA is an enterprise IT asset management and endpoint management appliance used for software deployment, patch management, hardware/software inventory, and device lifecycle management. The specific affected versions are listed in Quest's security advisory on the Quest Support Portal. Organizations should identify all KACE SMA instances in their environment, including any HA or replicated configurations.
How do I fix it?
Apply the patch provided by Quest in their security advisory for CVE-2025-32975. Updates are applied through the KACE SMA administrator console under Settings > General Settings > Quest KACE SMA Update. If immediate patching is not possible, restrict network access to the KACE SMA web interface to administrator-only network ranges and disable any internet exposure of the appliance. Rotate all credentials stored in KACE SMA's managed credentials store after patching.
How severe is it?
CVE-2025-32975 is Critical. An unauthenticated network attacker can impersonate any user on the platform — including administrators — without knowing their credentials. This grants full control of the KACE SMA console and all associated endpoint management capabilities, including software deployment to every managed device in the fleet. The 97.5th percentile EPSS score and confirmed KEV listing make this one of the highest-priority vulnerabilities in the current threat landscape.
Need Help With Vulnerability Management?
Our security experts can help you prioritize and remediate vulnerabilities effectively.