An issue was discovered in Quest KACE Desktop Authority before 11.2. This vulnerability allows attackers to execute remote code through a deserialization exploitation in the RadAsyncUpload function of ASP.NET AJAX. An attacker can leverage this vulnerability when the encryption keys are known (due to the presence of CVE-2017-11317, CVE-2017-11357, or other means). A default setting for the type whitelisting feature in more current versions of ASP.NET AJAX prevents exploitation.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-30888 An issue was discovered in Quest KACE Desktop Authority before 11.2. This vulnerability allows attackers to execute remote code through a deserialization exploitation in the RadAsyncUpload function of ASP.NET AJAX. An attacker can leverage this vulnerability when the encryption keys are known (due to the presence of CVE-2017-11317, CVE-2017-11357, or other means). A default setting for the type whitelisting feature in more current versions of ASP.NET AJAX prevents exploitation.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T04:10:17.203Z

Reserved: 2021-11-19T00:00:00

Link: CVE-2021-44029

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-12-22T06:15:07.013

Modified: 2024-11-21T06:30:14.990

Link: CVE-2021-44029

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.