CVE-2024-28988
moderateUnauthenticated Java Deserialization RCE in SolarWinds Web Help Desk
CVE-2024-28988 is a Java deserialization remote code execution flaw (CWE-502) in SolarWinds Web Help Desk that allows an attacker to run commands on the host machine running the application. It is triggered over the network by sending the application crafted input that is deserialized without adequate validation, and requires no authentication or user interaction (CVSS 3.1: AV:N/AC:L/PR:N/UI:N). Successful exploitation gives remote code execution with high impact on confidentiality, integrity, and availability (CVSS 3.1 score 9.8, critical). All Web Help Desk deployments running versions prior to the vendor's hotfix are affected; the flaw was discovered by the Trend Micro Zero Day Initiative (ZDI) team, which found it exploitable without authentication while researching a previously reported Web Help Desk vulnerability. As of this analysis there is no confirmed in-the-wild exploitation, no CISA KEV listing, and no known public PoC, but EPSS assigns a ~39.4% probability of exploitation within 30 days (99th percentile), so defenders should treat it as a high-priority patch.
What to do: Apply the hotfix SolarWinds has released for Web Help Desk immediately, per the vendor's advisory, since all customers are urged to patch. If patching is delayed, restrict network access to the Web Help Desk server — especially remove direct internet exposure — and monitor for unexpected command or child-process activity from the Web Help Desk service. Also inventory which of your instances are internet-facing and review their access logs for unauthenticated, suspicious requests.
| SolarWinds Web Help Desk | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. This vulnerability was found by the ZDI team after researching a previous vulnerability and providing this report. The ZDI team was able to discover an unauthenticated attack during their research. We recommend all Web Help Desk customers apply the patch, which is now available. We thank Trend Micro Zero Day Initiative (ZDI) for its ongoing partnership in coordinating with SolarWinds on responsible disclosure of this and other potential vulnerabilities.
- Vendors
- solarwinds
- Products
- web help desk
- Weakness
- CWE-502
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H