SolarWinds Urges Upgrade After Revealing Critical RCE Bug
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-28986 | Java Deserialization RCE in SolarWinds Web Help Desk SolarWinds Web Help Desk is susceptible to a Java deserialization of untrusted data flaw (CWE-502) in which maliciously crafted serialized Java data sent to the application can trigger remote code execution on the host machine. The flaw is rated 9.8 (network vector, no privileges or user interaction required), though SolarWinds has been unable to reproduce exploitation without authentication after thorough testing and recommends patching all deployments out of caution. A successful attacker gains the ability to run arbitrary commands on the Web Help Desk server, typically yielding control of the host and access to help-desk data. All Web Help Desk versions are potentially affected, and SolarWinds has released a hotfix/patch to address the issue. The bug is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-08-15, ordered federal agencies to patch by a Friday deadline, and EPSS estimates an 84.6% probability of exploitation within 30 days (100th percentile). Do: Upgrade every Web Help Desk deployment to the patched release per SolarWinds' security advisory (a hotfix addressing the issue in all versions is available); if immediate patching is not possible, restrict network access to the Web Help Desk web interface and watch the host for signs of command execution. Federal agencies must meet the CISA KEV remediation deadline, and defenders should also review SolarWinds' related Web Help Desk advisories (including the separately fixed hardcoded-credential issue) while patching. | 9.8 | 85% | KEV |
| moderateplausibly on the order of tens of thousands of on-premises deployments, with internet-exposed instances likely numbering in the low thousands |
Full article301 words · extracted from infosecurity-magazine.com · click to collapse
IT management software provider SolarWinds has urged customers to immediately patch a critical vulnerability in its Web Help Desk platform.
CVE-2024-28986 is a Java deserialization remote code execution (RCE) bug discovered by Inmarsat Government researchers, according to an advisory published yesterday.
“SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine,” it explained.
“While it was reported as an unauthenticated vulnerability, SolarWinds has been unable to reproduce it without authentication after thorough testing. However, out of an abundance of caution, we recommend all Web Help Desk customers apply the patch, which is now available.”
The vendor said that all versions of Web Help Desk (WHD) should be upgraded to WHD 12.8.3, and then the hotfix should be installed.
CVE-2024-28986 has been given a CVSS v3 score of 9.8, illustrating the criticality of patching the issue immediately. SolarWinds has published instructions on how to upgrade to WHD 12.8.3 and install the hotfix, as well as how to uninstall it if required.
Read more on SolarWinds: Three More Vulnerabilities Found in SolarWinds Products
The firm also suggested that customers backup several files before applying the hotfix.
SolarWind Faces Legal Scrutiny
In July a US judge dismissed most of the charges brought by the SEC against SolarWinds for a 2021 security breach which impacted thousands of customers.
He ruled that claims that SolarWinds and CISO Timothy Brown concealed the firm’s security weaknesses after the incident, thereby defrauding their investors, were based on “hindsight and speculation.”
The judge also dismissed SEC claims that the firm effectively hid cybersecurity weaknesses in its products before the attack.
However, he did rule that there are legitimate concerns about the failure of security controls embedded in SolarWinds products.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/solarwinds-upgrade-critical-rce-bug/