CVE-2021-44029

Severity CVSS v4.0:
Pending analysis
Type:
CWE-502 Deserialization of Untrusted Dat
Publication date:
22/12/2021
Last modified:
03/01/2022

Description

An issue was discovered in Quest KACE Desktop Authority before 11.2. This vulnerability allows attackers to execute remote code through a deserialization exploitation in the RadAsyncUpload function of ASP.NET AJAX. An attacker can leverage this vulnerability when the encryption keys are known (due to the presence of CVE-2017-11317, CVE-2017-11357, or other means). A default setting for the type whitelisting feature in more current versions of ASP.NET AJAX prevents exploitation.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:quest:kace_desktop_authority:*:*:*:*:*:*:*:* 10.0 (including) 11.2 (excluding)