---
title: "CVE-2025-32975"
url: https://daily.dev/posts/cve-2025-32975-4tolc5nip
source_url: https://arcticwolf.com/resources/blog/cve-2025-32975/
type: article
source: "Arctic Wolf"
published: 2026-03-19T21:07:49.007Z
updated: 2026-03-19T21:08:59.936Z
tags: ["security"]
reading_time: 3
upvotes: 0
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# CVE-2025-32975

**[Arctic Wolf](https://daily.dev/sources/arcticwolf)** · 3 min read · 0 upvotes · 0 comments

## Summary

Arctic Wolf has observed active exploitation of CVE-2025-32975, a critical authentication bypass vulnerability in Quest KACE Systems Management Appliance (SMA), starting the week of March 9, 2026. The flaw in the SSO authentication mechanism allows threat actors to impersonate users and achieve full administrative takeover without valid credentials. Observed post-exploitation activity includes remote command execution via KPluginRunProcess, credential harvesting with Mimikatz, creation of rogue admin accounts, PowerShell persistence scripts, domain enumeration, and lateral movement to backup infrastructure and domain controllers. The vulnerability was patched in May 2025. Recommendations include upgrading to the latest fixed version and removing KACE SMA instances from public internet exposure, restricting access via VPN or firewall.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://arcticwolf.com/resources/blog/cve-2025-32975/>

---

Tags: [#security](https://daily.dev/tags/security)

[View this post on daily.dev](https://daily.dev/posts/cve-2025-32975-4tolc5nip)
