An issue was discovered in Quest KACE Desktop Authority before 11.2. This vulnerability allows attackers to execute remote code through a deserialization exploitation in the RadAsyncUpload function of ASP.NET AJAX. An attacker can leverage this vulnerability when the encryption keys are known (due to the presence of CVE-2017-11317, CVE-2017-11357, or other means). A default setting for the type whitelisting feature in more current versions of ASP.NET AJAX prevents exploitation.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2021-12-22T05:08:42
Updated: 2024-08-04T04:10:17.203Z
Reserved: 2021-11-19T00:00:00
Link: CVE-2021-44029
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-12-22T06:15:07.013
Modified: 2024-11-21T06:30:14.990
Link: CVE-2021-44029
Redhat
No data.