Quest KACE Desktop Authority
cpe:2.3:a:quest:kace_desktop_authority:*:*:*:*:*:*:*
- <= 11.3.1
A vulnerability exists in Quest KACE Desktop Authority versions through 11.3.1, related to insecure permissions on Named Pipes used for inter-process communication. These Named Pipes were created without proper access controls, allowing unauthorized local users to potentially access them. This could lead to unintended interactions or privilege escalation within the application.
The vulnerability could be exploited by an unauthorized local user to access Named Pipes, potentially leading to unauthorized interactions or privilege escalation within the application context.
Quest has released a patch for this vulnerability in version 11.3.2, published on November 3, 2025. Users are advised to upgrade to Quest KACE Desktop Authority 11.3.2 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.