CVE-2025-32975 KACE SMA Breach Revealed HIQ Data and 60+ Downstream Clients

Summary
Hunt.io says attackers exploited KACE SMA's CVSS 10.0 authentication bypass to compromise HIQ, exposing a database tied to 60+ client organizations and a 308 MB post-exploitation toolkit. More than 12,000 internet-facing appliances reportedly show pre-patch versions.
Key points
- CVE-2025-32975 is an unauthenticated authentication bypass in KACE SMA SSO handling, rated CVSS 10.0; Quest released fixes in May 2025, and malicious activity was observed in March 2026.
- Hunt.io captured an unauthenticated directory on March 12, 2026, containing 219 files totaling 308 MB, including tools for reverse shells, persistence, credential spraying, reconnaissance, and tunneled access.
- A database dump identified the primary victim as HIQ, a managed IT services provider, and listed more than 60 client organizations whose endpoints were managed through its KACE appliance.
- The exposed database included HIQ operator account information, endpoint inventory, helpdesk data, and configuration details.
- Hunt.io reported more than 12,000 internet-facing KACE K1000 appliances disclosing version strings below the patch thresholds.
- The article recommends patching to fixed KACE SMA builds, blocking the reported command-and-control infrastructure, and checking for the kace_admin account and related activity.
Article Details
- Attack Vectors
- Exploitation of CVE-2025-32975 in internet-reachable KACE SMA appliances bypasses SSO authentication and permits impersonation of users, including administrators, without credentials.
- Compromise of the privileged endpoint-management appliance provides a potential delivery and remote-execution path to managed customer endpoints.
- Six staged Next.js prototype-pollution payloads manipulate server-action serialization and use arithmetic execution canaries to probe multiple routing segments for server-side code execution.
- The toolkit creates a local kace_admin account and adds it to Administrators and Remote Desktop Users to retain privileged access.
- SMB credential testing and C$ share validation support identification of credentials with administrative access to additional hosts.
- A victim-initiated TCP tunnel bridges an attacker-side SOCKS5 proxy to internal network destinations.
- Defensive Notes
- Patch KACE SMA to 13.0.385, 13.1.81, 13.2.183, 14.0.341 Patch 5, or 14.1.101 Patch 4. Reapply the security hotfix after every full version upgrade on the 13.x branch.
- Determine whether the appliance is publicly reachable; X-Kace-Appliance and X-Kace-Version response headers can identify exposed appliances and their reported versions. Non-standard ports do not prevent discovery.
- Block inbound and outbound traffic to the reported C2 address on all ports. Deny outbound TCP ports 23946, 9002, 9008, and 8000, and unapproved SOCKS5 destinations on port 1081.
- Search Windows hosts for kace_admin and review Security Event IDs 4720 and 4732 for its creation and group enrollment. Audit Remote Desktop Users membership, including SID S-1-5-32-555.
- Review PowerShell script-block logs for the exposed account password and the command pattern Add-LocalGroupMember -Group.*S-1-5-32-544.
- Alert on unexpected C$ share access in Event ID 5140, particularly when originating from the KACE SMA appliance.
- Inspect web application POST requests for proto or constructor.constructor in form values, and server logs for NEXT_REDIRECT exceptions accompanied by arithmetic expressions.
- Audit managed endpoints for unexpected scheduled tasks and newly created local administrator accounts after 2026-03-09.
- Review RDP logs on backup infrastructure and domain controllers for connections from the appliance or kace_admin during 2026-03-09 through 2026-03-14 and afterward.
- The report recommends treating HIQ customers with endpoints enrolled in the compromised appliance as downstream exposures; enrollment alone does not establish that every endpoint was compromised.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| IPV4 | 216[.]126[.]225[.]156 | C2 address written in the rs.py code sample as the reverse-shell destination on port 23946. |
| MD5 | 31c2ed150ab16d65ec2598e48ad975b0 | Hash of EWhere64.exe, the Earthworm tunneling binary staged in the attacker toolkit. |
| SHA256 | 02f4fa982b6ece6dc0796c28dcf3298953c2403664ff775e8a06ed3a9fef35cb | Hash of rs.py, the Python reverse shell staged on the C2 server. |
| SHA256 | 0f9a5b4fe71938761e48d5cbf8bd020b45115b3409f914821dcae06d8c4635be | Hash of 2.py, the operator-side SOCKS5 proxy and tunnel server. |
| SHA256 | 1942586138893c34d4b7693f6ab604a7cd812968045f0958aa97e56d7aca07ea | Hash of app, a staged Next.js prototype-pollution exploit payload. |
| SHA256 | 247243bd1b0836bc1c819bdfaef3e58d85c911a64c8ea6b4879d4e3b34cf2c1e | Hash of 1.py, the victim-side client for the custom TCP-multiplexed tunnel. |
| SHA256 | 56aed89edb4acfb6ef8de7fb9df5e790f332fbe89d02acc9a69fc874a4a817eb | Hash of uploaded_file, a staged Next.js prototype-pollution exploit payload. |
| SHA256 | 5a9d0c4b1961aacf678d35d9c5ffbf508586006387a62f1565f3c4698d11beae | Hash of _next, a staged Next.js prototype-pollution exploit payload. |
| SHA256 | 60bfce4d6015cb644042e69ef3e09587698c6b1fb746f819622b13372cc07927 | Hash of route, a staged Next.js prototype-pollution exploit payload. |
| SHA256 | 6979b0c5299c5630d3b7493a67fcfa704fd44fff81faf8990ad80c2c385e7cab | Hash of print_param.py, the attacker HTTP POST data receiver on port 9008. |
| SHA256 | 8919034ae60e81654cfe314eaffe7cde309067c8f338b8a46e0df908ae20ddf0 | Hash of EWhere64.exe, the Earthworm tunneling binary in the exposed toolkit. |
| SHA256 | 8bde9d57525b38039ac50e182d5734643020eb46f86807fc0f5d7ad2961d6246 | Hash of api, a staged Next.js prototype-pollution exploit payload. |
| SHA256 | 9f9da1b2bb70b63b8647d91468ab4000a6944523b8781086fc9eff76f23f071b | Hash of smb.py, the attacker SMB credential-testing and administrative-share validation script. |
| SHA256 | a7d32c3ff0cfee0d3faf18e54a43542ec10ec795c0fcd32f5c7c6e856cb1cd12 | Hash of server, a staged Next.js prototype-pollution exploit payload. |
| SHA256 | a8cab6ca6649b33146c8a0670e7226dd901928b0fd22a89af977dca9b50f2ed2 | Hash of cm_disk.ps1, the domain-wide WMI reconnaissance script containing victim credentials. |
| SHA256 | ad21a458b4271840f4afb215adf940d953e0aa0c089a10a6d62e5b8ff9c49423 | Hash of k.exe listed among the attacker toolkit file indicators; its function is not disclosed. |
| SHA256 | ba967c02f34b9f0b13b93a1517e2780985660dc2a18078f8e552161e4fb65403 | Hash of AddUser.ps1, the script creating the privileged kace_admin backdoor account. |
| SHA256 | e45aad4e549d182f509a508d1daeeb5199ab33cf033515c7fe310c6e90a97467 | Hash of uploadserver.py, the C2 HTTP server used for toolkit downloads and inbound file uploads. |
MITRE ATT&CK
T1005 · Data from Local SystemThe C2 directory contained sql.zip, an exported production KACE SMA database with account, inventory, ticket, and configuration data.T1018 · Remote System Discoverycm_disk.ps1 enumerates Active Directory computer objects and resolves their addresses; nbtscan supports network host discovery.T1021.001 · Remote Desktop ProtocolThe article maps RDP access to backup infrastructure and domain controllers and describes persistence through Remote Desktop Users membership.T1021.002 · SMB/Windows Admin Sharessmb.py authenticates to remote SMB services and attempts to mount C$ to validate administrative access.T1033 · System Owner/User Discoverycm_disk.ps1 queries Win32_ComputerSystem to collect the currently logged-in user on each reachable host.T1041 · Exfiltration Over C2 ChannelThe same C2 infrastructure accepts uploaded files through uploadserver.py and POST data through print_param.py.T1046 · Network Service DiscoveryThe staged toolkit includes nbtscan for NetBIOS network scanning; the article also maps nc.exe to scanning.T1059.001 · PowerShellAddUser.ps1 and share.txt create privileged accounts, while cm_disk.ps1 performs domain-wide reconnaissance through PowerShell.T1059.004 · Unix Shellrs.py redirects standard file descriptors to its callback socket and launches /bin/sh -i.T1059.006 · PythonThe toolkit uses Python for rs.py, SMB credential testing, HTTP data reception, and the custom tunnel components.T1069 · Permission Groups DiscoveryThe article's mapping identifies net group enumeration in the intrusion toolkit.T1082 · System Information Discoverycm_disk.ps1 queries remote WMI/CIM classes for operating system, uptime, and disk capacity and utilization.T1090 · Proxy2.py exposes a SOCKS5 proxy on port 1081 and relays requests through the victim-side tunnel to internal destinations.T1090.003 · Multi-hop ProxyThe report assesses the staged Tor Browser installation as supporting anonymous operator network access.T1098 · Account ManipulationThe persistence scripts enroll kace_admin in Administrators and Remote Desktop Users.T1105 · Ingress Tool Transferuploadserver.py serves attacker toolkit files to victims through HTTP GET requests on port 8000.T1110.003 · Password SprayingThe article identifies smb.py as an SMB credential sprayer that tests supplied username/password combinations against hosts.T1119 · Automated Collectionprint_param.py automatically reads and prints incoming HTTP POST bodies on port 9008.T1136.001 · Local AccountAddUser.ps1 and share.txt create the local kace_admin account for persistent access.T1190 · Exploit Public-Facing ApplicationThe report describes exploitation of internet-facing KACE SMA authentication handling and staged Next.js prototype-pollution payloads probing server-side execution.T1572 · Protocol Tunneling1.py and 2.py multiplex internal connections through a framed TCP tunnel on port 9002; EWhere64.exe provides another tunneling option.
CVE
CVE-2025-32975CVE-2025-32975 is a critical authentication bypass vulnerability in KACE SMA's SSO authentication handling mechanism with a CVSS score of 10.0. The flaw allows an unauthenticated, network-reachable attacker toCVE-2025-32977May 27, 2025 Quest publishes advisory and fixed builds for CVE-2025-32975 and related CVEs (CVE-2025--32976, CVE-2025-32977, CVE-2025-32978)CVE-2025-32978May 27, 2025 Quest publishes advisory and fixed builds for CVE-2025-32975 and related CVEs (CVE-2025--32976, CVE-2025-32977, CVE-2025-32978)
Vendors
QuestQuest KACE Systems Management Appliance (SMA) is a widely deployed on-premises platform that enterprises use for endpoint management, handling software deployment, patch distribution, inventory, and scriptedRouterHosting LLCUsing Hunt.io AttackCaptureâ¢, we identified an exposed file directory hosted at 216.126.225[.]156:8000 on March 12, 2026, located on infrastructure operated by RouterHosting LLC.
Products
KACE K1000The dump spans 29,092 lines of SQL encompassing the complete KACE K1000 application database, including user accounts, managed client inventory, helpdesk ticket queues, role permissions, automation scripts, andMariaDBThe exfiltrated MariaDB dump reveals the appliance-managed endpoints for over 60 named client organizations spanning law enforcement, government, healthcare, education, and the private sector.Next.jsSix Next.js prototype pollution exploit payloads (uploaded_file, server, route, api, app, _next) were found alongside the KACE toolkit.Quest KACE Systems Management Appliance (SMA)Quest KACE Systems Management Appliance (SMA) is a widely deployed on-premises platform that enterprises use for endpoint management, handling software deployment, patch distribution, inventory, and scriptedSessionLNK file forensics from Tor_20Browser.lnk and Session.lnk attribute the operator to a Windows Server 2019 machine with hostname windows-utah-8g, consistent with a rented VPS, operating as the built-in Administrator (SIDTor BrowserMoreover, a full Tor Browser package (~256 MB) was also present, suggesting the operator relied on anonymity networks for operational access to the command-and-control environment.Windows Server 2019LNK file forensics from Tor_20Browser.lnk and Session.lnk attribute the operator to a Windows Server 2019 machine with hostname windows-utah-8g, consistent with a rented VPS, operating as the built-in Administrator (SID
Tools
1.py1.py 4 KB Tunnel client (victim-side, connects to C2 port 9002) T1572 Protocol Tunneling2.py2.py 5 KB SOCKS5 multiplexing proxy server (operator-side) T1572, T1090 ProxyAddUser.ps1The presence of PowerShell scripts (AddUser.ps1, cm_disk.ps1), Python utilities, and network tools (nc.exe) indicates the server functioned as a centralized toolkit repository supporting reconnaissance, persistence, andAttackCapturea critical authentication bypass. Finding the attacker's toolkit required nothing more than Hunt.io AttackCapture identifying an exposed open directory on a publicly reachable server. Organizations that continuouslycm_disk.ps1The presence of PowerShell scripts (AddUser.ps1, cm_disk.ps1), Python utilities, and network tools (nc.exe) indicates the server functioned as a centralized toolkit repository supporting reconnaissance, persistence, andEarthwormtooling, including network reconnaissance utilities (such as nbtscan), tunneling and proxy tools like Earthworm (EWhere64.exe), scripts for lateral movement and exploitation (e.g., smb.py, rs.py, and share.txt), andHuntSQLHunt.io's HuntSQL dataset currently shows more than 12,000 internet-facing K1000 instances actively disclosing these headers, with every visible version falling below the patch thresholds for CVE-2025-32975.nbtscanexposed a wide range of post-exploitation tooling, including network reconnaissance utilities (such as nbtscan), tunneling and proxy tools like Earthworm (EWhere64.exe), scripts for lateral movement and exploitationnetcatof tools and scripts within the exposed C2 directory, including Earthworm tunneling binaries, nbtscan, netcat, PowerShell scripts, and Python exploitation utilities, highlighting the infrastructure used to supportprint_param.pyprint_param.py 933 B HTTP POST logger/data capture on port 9008 T1119 Automated Collectionrs.pyproxy tools like Earthworm (EWhere64.exe), scripts for lateral movement and exploitation (e.g., smb.py, rs.py, and share.txt), and a large archive (sql.zip, ~50 MB) likely containing victim data.smb.pyand proxy tools like Earthworm (EWhere64.exe), scripts for lateral movement and exploitation (e.g., smb.py, rs.py, and share.txt), and a large archive (sql.zip, ~50 MB) likely containing victim data.uploadserver.pyuploadserver.py 747 B C2 bidirectional file server T1105 Ingress Tool Transfer
Countries
Industries
EducationThe exfiltrated MariaDB dump reveals the appliance-managed endpoints for over 60 named client organizations spanning law enforcement, government, healthcare, education, and the private sector.GovernmentThe exfiltrated MariaDB dump reveals the appliance-managed endpoints for over 60 named client organizations spanning law enforcement, government, healthcare, education, and the private sector.HealthcareThe exfiltrated MariaDB dump reveals the appliance-managed endpoints for over 60 named client organizations spanning law enforcement, government, healthcare, education, and the private sector.InsuranceA hardcoded domain administrator credential for BRI Insurance, an Indonesian insurance company, is embedded in cm_disk.ps1 confirms that at least one additional environment was fully compromised before this toolkit wasLaw enforcementThe exfiltrated MariaDB dump reveals the appliance-managed endpoints for over 60 named client organizations spanning law enforcement, government, healthcare, education, and the private sector.managed IT servicesinfrastructure and operational workflow. The primary victim identified in the data is HIQ, a managed IT services provider in the Boston area whose KACE appliance managed endpoints for over 60 named clientprivate sectorThe exfiltrated MariaDB dump reveals the appliance-managed endpoints for over 60 named client organizations spanning law enforcement, government, healthcare, education, and the private sector.