CVE-2025-40553
moderateUnauthenticated Deserialization RCE in SolarWinds Web Help Desk
SolarWinds Web Help Desk contains a critical untrusted data deserialization flaw (CWE-502) that is reachable over the network without any authentication. By sending crafted serialized data to a vulnerable instance, an attacker can trigger remote code execution and run arbitrary commands on the underlying host machine. Any organization running SolarWinds Web Help Desk is affected, and instances exposed to the internet carry the highest risk because the flaw requires no privileges or user interaction (CVSS 9.8, AV:N/AC:L/PR:N/UI:N). Exploitation likelihood is rated very high (EPSS ~60.4% within 30 days, 99th percentile), and recent reporting describes active exploitation of unauthenticated Web Help Desk RCE flaws, though the CVE record itself does not yet list this entry in CISA's KEV catalog. No public proof-of-concept code is documented in the available data.
What to do: Upgrade SolarWinds Web Help Desk to the patched release identified in the SolarWinds PSIRT advisory covering this CVE and the related batch of four critical WHD fixes (check your current version against the advisory since exact affected ranges are not listed here). Until patched, do not expose the Web Help Desk service directly to the internet and restrict access to trusted networks only. Given reporting of active exploitation of these unauthenticated RCE flaws, prioritize internet-facing instances and monitor hosts for signs of command execution.
| SolarWinds Web Help Desk | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication.
- Vendors
- solarwinds
- Products
- web help desk
- Weakness
- CWE-502
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H