Jeffrey Hofmann: Pre-Auth RCE Chains in MDM — Full Compromise of KACE SMA
A DEF CON 30 talk covering three pre-authentication RCE chains in KACE Systems Management Appliance (KACE SMA), a popular MDM solution by Quest. Because an MDM manages devices across an entire organization — including executing tasks with root/system privileges — its compromise effectively means full control over the infrastructure.
The talk walks through the research process in detail: from obtaining an initial shell and reversing PHP code to discovering SQL injection vulnerabilities, authentication bypasses, session logic flaws, and command injection. It demonstrates how these issues can be chained together — from an unauthenticated request to root-level code execution and mass command execution across managed endpoints.
The talk walks through the research process in detail: from obtaining an initial shell and reversing PHP code to discovering SQL injection vulnerabilities, authentication bypasses, session logic flaws, and command injection. It demonstrates how these issues can be chained together — from an unauthenticated request to root-level code execution and mass command execution across managed endpoints.