CVE-2025-32975 KACE SMA Breach Revealed HIQ Data and 60+ Downstream Clients

· Original article ↗

Summary

Hunt.io says attackers exploited KACE SMA's CVSS 10.0 authentication bypass to compromise HIQ, exposing a database tied to 60+ client organizations and a 308 MB post-exploitation toolkit. More than 12,000 internet-facing appliances reportedly show pre-patch versions.

Key points

  • CVE-2025-32975 is an unauthenticated authentication bypass in KACE SMA SSO handling, rated CVSS 10.0; Quest released fixes in May 2025, and malicious activity was observed in March 2026.
  • Hunt.io captured an unauthenticated directory on March 12, 2026, containing 219 files totaling 308 MB, including tools for reverse shells, persistence, credential spraying, reconnaissance, and tunneled access.
  • A database dump identified the primary victim as HIQ, a managed IT services provider, and listed more than 60 client organizations whose endpoints were managed through its KACE appliance.
  • The exposed database included HIQ operator account information, endpoint inventory, helpdesk data, and configuration details.
  • Hunt.io reported more than 12,000 internet-facing KACE K1000 appliances disclosing version strings below the patch thresholds.
  • The article recommends patching to fixed KACE SMA builds, blocking the reported command-and-control infrastructure, and checking for the kace_admin account and related activity.

Article Details

Attack Vectors
  • Exploitation of CVE-2025-32975 in internet-reachable KACE SMA appliances bypasses SSO authentication and permits impersonation of users, including administrators, without credentials.
  • Compromise of the privileged endpoint-management appliance provides a potential delivery and remote-execution path to managed customer endpoints.
  • Six staged Next.js prototype-pollution payloads manipulate server-action serialization and use arithmetic execution canaries to probe multiple routing segments for server-side code execution.
  • The toolkit creates a local kace_admin account and adds it to Administrators and Remote Desktop Users to retain privileged access.
  • SMB credential testing and C$ share validation support identification of credentials with administrative access to additional hosts.
  • A victim-initiated TCP tunnel bridges an attacker-side SOCKS5 proxy to internal network destinations.
Defensive Notes
  • Patch KACE SMA to 13.0.385, 13.1.81, 13.2.183, 14.0.341 Patch 5, or 14.1.101 Patch 4. Reapply the security hotfix after every full version upgrade on the 13.x branch.
  • Determine whether the appliance is publicly reachable; X-Kace-Appliance and X-Kace-Version response headers can identify exposed appliances and their reported versions. Non-standard ports do not prevent discovery.
  • Block inbound and outbound traffic to the reported C2 address on all ports. Deny outbound TCP ports 23946, 9002, 9008, and 8000, and unapproved SOCKS5 destinations on port 1081.
  • Search Windows hosts for kace_admin and review Security Event IDs 4720 and 4732 for its creation and group enrollment. Audit Remote Desktop Users membership, including SID S-1-5-32-555.
  • Review PowerShell script-block logs for the exposed account password and the command pattern Add-LocalGroupMember -Group.*S-1-5-32-544.
  • Alert on unexpected C$ share access in Event ID 5140, particularly when originating from the KACE SMA appliance.
  • Inspect web application POST requests for proto or constructor.constructor in form values, and server logs for NEXT_REDIRECT exceptions accompanied by arithmetic expressions.
  • Audit managed endpoints for unexpected scheduled tasks and newly created local administrator accounts after 2026-03-09.
  • Review RDP logs on backup infrastructure and domain controllers for connections from the appliance or kace_admin during 2026-03-09 through 2026-03-14 and afterward.
  • The report recommends treating HIQ customers with endpoints enrolled in the compromised appliance as downstream exposures; enrollment alone does not establish that every endpoint was compromised.

Indicators of compromise

TypeIndicatorContext
IPV4216[.]126[.]225[.]156C2 address written in the rs.py code sample as the reverse-shell destination on port 23946.
MD531c2ed150ab16d65ec2598e48ad975b0Hash of EWhere64.exe, the Earthworm tunneling binary staged in the attacker toolkit.
SHA25602f4fa982b6ece6dc0796c28dcf3298953c2403664ff775e8a06ed3a9fef35cbHash of rs.py, the Python reverse shell staged on the C2 server.
SHA2560f9a5b4fe71938761e48d5cbf8bd020b45115b3409f914821dcae06d8c4635beHash of 2.py, the operator-side SOCKS5 proxy and tunnel server.
SHA2561942586138893c34d4b7693f6ab604a7cd812968045f0958aa97e56d7aca07eaHash of app, a staged Next.js prototype-pollution exploit payload.
SHA256247243bd1b0836bc1c819bdfaef3e58d85c911a64c8ea6b4879d4e3b34cf2c1eHash of 1.py, the victim-side client for the custom TCP-multiplexed tunnel.
SHA25656aed89edb4acfb6ef8de7fb9df5e790f332fbe89d02acc9a69fc874a4a817ebHash of uploaded_file, a staged Next.js prototype-pollution exploit payload.
SHA2565a9d0c4b1961aacf678d35d9c5ffbf508586006387a62f1565f3c4698d11beaeHash of _next, a staged Next.js prototype-pollution exploit payload.
SHA25660bfce4d6015cb644042e69ef3e09587698c6b1fb746f819622b13372cc07927Hash of route, a staged Next.js prototype-pollution exploit payload.
SHA2566979b0c5299c5630d3b7493a67fcfa704fd44fff81faf8990ad80c2c385e7cabHash of print_param.py, the attacker HTTP POST data receiver on port 9008.
SHA2568919034ae60e81654cfe314eaffe7cde309067c8f338b8a46e0df908ae20ddf0Hash of EWhere64.exe, the Earthworm tunneling binary in the exposed toolkit.
SHA2568bde9d57525b38039ac50e182d5734643020eb46f86807fc0f5d7ad2961d6246Hash of api, a staged Next.js prototype-pollution exploit payload.
SHA2569f9da1b2bb70b63b8647d91468ab4000a6944523b8781086fc9eff76f23f071bHash of smb.py, the attacker SMB credential-testing and administrative-share validation script.
SHA256a7d32c3ff0cfee0d3faf18e54a43542ec10ec795c0fcd32f5c7c6e856cb1cd12Hash of server, a staged Next.js prototype-pollution exploit payload.
SHA256a8cab6ca6649b33146c8a0670e7226dd901928b0fd22a89af977dca9b50f2ed2Hash of cm_disk.ps1, the domain-wide WMI reconnaissance script containing victim credentials.
SHA256ad21a458b4271840f4afb215adf940d953e0aa0c089a10a6d62e5b8ff9c49423Hash of k.exe listed among the attacker toolkit file indicators; its function is not disclosed.
SHA256ba967c02f34b9f0b13b93a1517e2780985660dc2a18078f8e552161e4fb65403Hash of AddUser.ps1, the script creating the privileged kace_admin backdoor account.
SHA256e45aad4e549d182f509a508d1daeeb5199ab33cf033515c7fe310c6e90a97467Hash of uploadserver.py, the C2 HTTP server used for toolkit downloads and inbound file uploads.

MITRE ATT&CK

T1005 · Data from Local SystemThe C2 directory contained sql.zip, an exported production KACE SMA database with account, inventory, ticket, and configuration data.T1018 · Remote System Discoverycm_disk.ps1 enumerates Active Directory computer objects and resolves their addresses; nbtscan supports network host discovery.T1021.001 · Remote Desktop ProtocolThe article maps RDP access to backup infrastructure and domain controllers and describes persistence through Remote Desktop Users membership.T1021.002 · SMB/Windows Admin Sharessmb.py authenticates to remote SMB services and attempts to mount C$ to validate administrative access.T1033 · System Owner/User Discoverycm_disk.ps1 queries Win32_ComputerSystem to collect the currently logged-in user on each reachable host.T1041 · Exfiltration Over C2 ChannelThe same C2 infrastructure accepts uploaded files through uploadserver.py and POST data through print_param.py.T1046 · Network Service DiscoveryThe staged toolkit includes nbtscan for NetBIOS network scanning; the article also maps nc.exe to scanning.T1059.001 · PowerShellAddUser.ps1 and share.txt create privileged accounts, while cm_disk.ps1 performs domain-wide reconnaissance through PowerShell.T1059.004 · Unix Shellrs.py redirects standard file descriptors to its callback socket and launches /bin/sh -i.T1059.006 · PythonThe toolkit uses Python for rs.py, SMB credential testing, HTTP data reception, and the custom tunnel components.T1069 · Permission Groups DiscoveryThe article's mapping identifies net group enumeration in the intrusion toolkit.T1082 · System Information Discoverycm_disk.ps1 queries remote WMI/CIM classes for operating system, uptime, and disk capacity and utilization.T1090 · Proxy2.py exposes a SOCKS5 proxy on port 1081 and relays requests through the victim-side tunnel to internal destinations.T1090.003 · Multi-hop ProxyThe report assesses the staged Tor Browser installation as supporting anonymous operator network access.T1098 · Account ManipulationThe persistence scripts enroll kace_admin in Administrators and Remote Desktop Users.T1105 · Ingress Tool Transferuploadserver.py serves attacker toolkit files to victims through HTTP GET requests on port 8000.T1110.003 · Password SprayingThe article identifies smb.py as an SMB credential sprayer that tests supplied username/password combinations against hosts.T1119 · Automated Collectionprint_param.py automatically reads and prints incoming HTTP POST bodies on port 9008.T1136.001 · Local AccountAddUser.ps1 and share.txt create the local kace_admin account for persistent access.T1190 · Exploit Public-Facing ApplicationThe report describes exploitation of internet-facing KACE SMA authentication handling and staged Next.js prototype-pollution payloads probing server-side execution.T1572 · Protocol Tunneling1.py and 2.py multiplex internal connections through a framed TCP tunnel on port 9002; EWhere64.exe provides another tunneling option.

CVE

Vendors

Products

Tools

1.py1.py 4 KB Tunnel client (victim-side, connects to C2 port 9002) T1572 Protocol Tunneling2.py2.py 5 KB SOCKS5 multiplexing proxy server (operator-side) T1572, T1090 ProxyAddUser.ps1The presence of PowerShell scripts (AddUser.ps1, cm_disk.ps1), Python utilities, and network tools (nc.exe) indicates the server functioned as a centralized toolkit repository supporting reconnaissance, persistence, andAttackCapturea critical authentication bypass. Finding the attacker's toolkit required nothing more than Hunt.io AttackCapture identifying an exposed open directory on a publicly reachable server. Organizations that continuouslycm_disk.ps1The presence of PowerShell scripts (AddUser.ps1, cm_disk.ps1), Python utilities, and network tools (nc.exe) indicates the server functioned as a centralized toolkit repository supporting reconnaissance, persistence, andEarthwormtooling, including network reconnaissance utilities (such as nbtscan), tunneling and proxy tools like Earthworm (EWhere64.exe), scripts for lateral movement and exploitation (e.g., smb.py, rs.py, and share.txt), andHuntSQLHunt.io's HuntSQL dataset currently shows more than 12,000 internet-facing K1000 instances actively disclosing these headers, with every visible version falling below the patch thresholds for CVE-2025-32975.nbtscanexposed a wide range of post-exploitation tooling, including network reconnaissance utilities (such as nbtscan), tunneling and proxy tools like Earthworm (EWhere64.exe), scripts for lateral movement and exploitationnetcatof tools and scripts within the exposed C2 directory, including Earthworm tunneling binaries, nbtscan, netcat, PowerShell scripts, and Python exploitation utilities, highlighting the infrastructure used to supportprint_param.pyprint_param.py 933 B HTTP POST logger/data capture on port 9008 T1119 Automated Collectionrs.pyproxy tools like Earthworm (EWhere64.exe), scripts for lateral movement and exploitation (e.g., smb.py, rs.py, and share.txt), and a large archive (sql.zip, ~50 MB) likely containing victim data.smb.pyand proxy tools like Earthworm (EWhere64.exe), scripts for lateral movement and exploitation (e.g., smb.py, rs.py, and share.txt), and a large archive (sql.zip, ~50 MB) likely containing victim data.uploadserver.pyuploadserver.py 747 B C2 bidirectional file server T1105 Ingress Tool Transfer

Countries

Industries

Related Articles