VYPR
Critical severity9.8NVD Advisory· Published Dec 22, 2021· Updated Jun 17, 2026

CVE-2021-44031

CVE-2021-44031

Description

An issue was discovered in Quest KACE Desktop Authority before 11.2. /dacomponentui/profiles/profileitems/outlooksettings/Insertimage.aspx contains a vulnerability that could allow pre-authentication remote code execution. An attacker could upload a .ASP file to reside at /images/{GUID}/{filename}.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:quest:kace_desktop_authority:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:quest:kace_desktop_authority:*:*:*:*:*:*:*:*range: <11.2
    • (no CPE)range: <11.2
  • Quest/KACE Desktop Authoritydescription

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.