OSV 1.4.0 · unreviewed · 修改于 2022-01-04 08:01
发布时间
2021-12-23 08:01
GitHub 审查时间
—
NVD 发布时间
2021-12-22 14:15
源文件
advisories/unreviewed/2021/12/GHSA-c7j6-8r6v-p532/GHSA-c7j6-8r6v-p532.json
An issue was discovered in Quest KACE Desktop Authority before 11.2. This vulnerability allows attackers to execute remote code through a deserialization exploitation in the RadAsyncUpload function of ASP.NET AJAX. An attacker can leverage this vulnerability when the encryption keys are known (due to the presence of CVE-2017-11317, CVE-2017-11357, or other means). A default setting for the type whitelisting feature in more current versions of ASP.NET AJAX prevents exploitation.
该公告没有提供结构化的受影响软件包信息。