CVE-2025-67813General(quest / kace_desktop_authority)

LOWCVSS 5.3 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch quest kace_desktop_authority systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Quest KACE Desktop Authority through 11.3.1 has Insecure Permissions on the Named Pipes used for inter-process communication

2.0/ 10 priority

Sources & remediation

Other references
Weakness type (CWE)
CWE-276

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • kace_desktop_authority

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 3 classified signals
  • Disclosure: 1 classified signal
  • Peaked 3d ago at 2 mentions (2026-02-05); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
kace_desktop_authority

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-02-05: 2Mentions · 2026-02-09: 1Mentions · 2026-02-10: 1Mentions · 2026-02-11: 1PoC Mentioned / Linked · 2026-02-05: 1Patch / Workaround · 2026-02-05: 1Technical Details · 2026-02-05: 202-0502-0902-1002-11
Signal classification3 categories
General
360.0%
Disclosure
120.0%
PoC
120.0%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-02-052
Disclosure1PoC1
2026-02-091
General1
2026-02-101
General1
2026-02-111
General1
Full discourse5 posts
  • NetSPI@NetSPI
    Disclosure

    NetSPI Principal Consultant Ceri Coburn identified a high-risk vulnerability (CVE-2025-67813) within Quest Desktop Authority that could allow attackers to execute remote code with SYSTEM privileges. Get the details: https://ow.ly/Zpgg50Y7Cg1 https://t.co/QrBoliWNc4

    Post summary

    NetSPI identified a high‑risk CVE‑2025‑67813 in Quest Desktop Authority that allows remote code execution with SYSTEM privileges; detailed information can be accessed via the provided link.

    04072965
    4.0K followersView on X
  • ET Labs@ET_Labs
    General

    72 new OPEN, 91 new PRO (72 + 19) Several New RMMs, Dynamic_DNS, Lumma Stealer, ZPHP, LandUpdate808, zgRAT, and several CVES (Quest KACE Desktop Authority -- CVE-2025-67813, Progress Software Kemp LoadMaster -- CVE-2025-13447) and more. https://community.emergingthreats.net/t/ruleset-update-summary-2026-02-09-v11121/3191

    Post summary

    The content lists CVE identifiers as part of a ruleset update but provides no additional technical, exploit, or mitigation details.

    020111.1K
    5.7K followersView on X
  • Mr. OS@ksg93rd
    PoC

    #exploit #AppSec 1⃣. CVE-2025-67813: RCE via Quest Desktop Authority Named Pipe https://www.netspi.com/blog/technical-blog/adversary-simulation/pipe-dreams-remote-code-execution-via-quest-desktop-authority-named-pipe // A vulnerability in Quest Desktop Authority allows authenticated users to remotely execute code and perform malicious operations via a named pipe, which can be mitigated by patches, firewalls, or disabling the service 2⃣. CVE-2026-24002: RCE sandbox escape in Grist‑Core https://www.cyera.com/research-labs/cellbreak-grists-pyodide-sandbox-escape-and-the-data-at-risk-blast-radius // One malicious formula can turn a spreadsheet into a RCE beachhead... 3⃣. CVE-2025-49825: Teleport remote authentication bypass https://blog.offensive.af/posts/exploiting-cve-2025-49825 // CVE-2025-49825 is a critical Teleport vulnerability allowing attackers to bypass authentication and potentially gain root access via nested SSH certificates if unpatched

    Post summary

    The post announces three CVEs with detailed exploitation methods and provides links to PoC blogs, but it does not report active exploitation or provide explicit exploit code.

    10011255
    3.1K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-1281 2 - CVE-2026-21509 3 - CVE-2026-21643 4 - CVE-2026-1529 5 - CVE-2025-67813 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post simply lists trending CVE identifiers without providing any technical details, exploitation evidence, or mitigation information.

    00020283
    1.7K followersView on X
  • ET Labs@ET_Labs
    General

    19 new OPEN, 32 new PRO (19 + 13) Quest KACE Desktop Insecure Named Pipe (CVE-2025-67813), Roundcube Webmail SVG felImage Remote Image Bypass (CVE-2026-25916) , ZPHP, LandUpdate808, Evil Keitaro, TA569 and more. https://community.emergingthreats.net/t/ruleset-update-summary-2026-02-10-v11122/3193

    Post summary

    The update lists two new CVEs (CVE-2025-67813 and CVE-2026-25916) in a rule set summary without providing exploitation details or patches.

    01010255
    5.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appquestkace_desktop_authority---

Explore more