ZeroHour

CVE-2024-28988

moderate

Unauthenticated Java Deserialization RCE in SolarWinds Web Help Desk

CVSS 3.1
9.8 critical
EPSS
39%p99
Published
()
Modified
AI analysis

CVE-2024-28988 is a Java deserialization remote code execution flaw (CWE-502) in SolarWinds Web Help Desk that allows an attacker to run commands on the host machine running the application. It is triggered over the network by sending the application crafted input that is deserialized without adequate validation, and requires no authentication or user interaction (CVSS 3.1: AV:N/AC:L/PR:N/UI:N). Successful exploitation gives remote code execution with high impact on confidentiality, integrity, and availability (CVSS 3.1 score 9.8, critical). All Web Help Desk deployments running versions prior to the vendor's hotfix are affected; the flaw was discovered by the Trend Micro Zero Day Initiative (ZDI) team, which found it exploitable without authentication while researching a previously reported Web Help Desk vulnerability. As of this analysis there is no confirmed in-the-wild exploitation, no CISA KEV listing, and no known public PoC, but EPSS assigns a ~39.4% probability of exploitation within 30 days (99th percentile), so defenders should treat it as a high-priority patch.

What to do: Apply the hotfix SolarWinds has released for Web Help Desk immediately, per the vendor's advisory, since all customers are urged to patch. If patching is delayed, restrict network access to the Web Help Desk server — especially remove direct internet exposure — and monitor for unexpected command or child-process activity from the Web Help Desk service. Also inventory which of your instances are internet-facing and review their access logs for unauthenticated, suspicious requests.

Affected
SolarWinds Web Help Desk
Estimated exposure
moderate≈1,000–10,000 internet-exposed Web Help Desk instances (public internet-wide scans); total on-prem install base likely in the low tens of thousands — Web Help Desk is a legacy, commercially licensed on-prem help desk product typically deployed as a single server per organization and usually kept on internal networks, and public internet-wide scans have surfaced only on the order of a…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. This vulnerability was found by the ZDI team after researching a previous vulnerability and providing this report. The ZDI team was able to discover an unauthenticated attack during their research. We recommend all Web Help Desk customers apply the patch, which is now available. We thank Trend Micro Zero Day Initiative (ZDI) for its ongoing partnership in coordinating with SolarWinds on responsible disclosure of this and other potential vulnerabilities.

Vendors
solarwinds
Products
web help desk
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news