ZeroHour

CVE-2016-3643

KEV PoC ×2moderate

Local Privilege Escalation in SolarWinds Virtualization Manager 6.3.1 and earlier

CISA: SolarWinds Virtualization Manager Privilege Escalation Vulnerability

CVSS 3.1
7.8 high
EPSS
4%p89
Published
()
KEV added
AI analysis

SolarWinds Virtualization Manager 6.3.1 and earlier ship with a misconfigured sudo setting that allows any local user on the appliance to execute commands with elevated (root) privileges. An attacker who has obtained any low-privilege foothold on the appliance, for example via another flaw or a weak account, can abuse the overly permissive sudo configuration (demonstrated with 'sudo cat /etc/passwd') to run arbitrary commands as root. Successful exploitation yields full control of the virtual appliance, including its stored data and credentials. Any deployment running Virtualization Manager 6.3.1 or earlier is affected. The flaw has had public proof-of-concept code since 2016 and was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03, indicating it has been exploited in the wild.

What to do: Upgrade Virtualization Manager to a release later than 6.3.1 per vendor instructions and verify the appliance's sudoers configuration no longer grants unrestricted root commands to low-privilege users. Because the flaw is on CISA's KEV list, prioritize patching internet-reachable appliances, restrict local shell access to trusted administrators, and review appliance logs and local accounts for signs of prior exploitation.

Affected
SolarWinds Virtualization Manager6.3.1 and earlier
Estimated exposure
moderateroughly 1,000–10,000 deployed virtual appliances — Virtualization Manager is a niche SolarWinds monitoring module typically deployed as a single virtual appliance per customer environment, implying an install base in the low thousands; exact deployment counts have not been published.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

SolarWinds Virtualization Manager 6.3.1 and earlier allow local users to gain privileges by leveraging a misconfiguration of sudo, as demonstrated by "sudo cat /etc/passwd."

CISA Known Exploited Vulnerability
Affected
SolarWinds Virtualization Manager
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
solarwinds
Products
virtualization manager
Weakness
CWE-264
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.