ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Critical RCE bug in SolarWinds Web Help Desk fixed (CVE-2024-28986)

criticalVulnerability exploited in the wildimportance 60CVE-2024-28986

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-28986
Java Deserialization RCE in SolarWinds Web Help Desk

SolarWinds Web Help Desk is susceptible to a Java deserialization of untrusted data flaw (CWE-502) in which maliciously crafted serialized Java data sent to the application can trigger remote code execution on the host machine. The flaw is rated 9.8 (network vector, no privileges or user interaction required), though SolarWinds has been unable to reproduce exploitation without authentication after thorough testing and recommends patching all deployments out of caution. A successful attacker gains the ability to run arbitrary commands on the Web Help Desk server, typically yielding control of the host and access to help-desk data. All Web Help Desk versions are potentially affected, and SolarWinds has released a hotfix/patch to address the issue. The bug is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-08-15, ordered federal agencies to patch by a Friday deadline, and EPSS estimates an 84.6% probability of exploitation within 30 days (100th percentile).

Do: Upgrade every Web Help Desk deployment to the patched release per SolarWinds' security advisory (a hotfix addressing the issue in all versions is available); if immediate patching is not possible, restrict network access to the Web Help Desk web interface and watch the host for signs of command execution. Federal agencies must meet the CISA KEV remediation deadline, and defenders should also review SolarWinds' related Web Help Desk advisories (including the separately fixed hardcoded-credential issue) while patching.

9.885% KEV
  • SolarWinds Web Help Desk all versions prior to the vendor hotfix/patch (SolarWinds stated the critical RCE affected all Web Help Desk versions; upgrade to the latest patched release per
moderateplausibly on the order of tens of thousands of on-premises deployments, with internet-exposed instances likely numbering in the low thousands
Full article387 words · extracted from helpnetsecurity.com · click to collapse

SolarWinds has fixed a critical vulnerability (CVE-2024-28986) in its Web Help Desk (WHD) solution that may allow attackers to run commands on the host machine.

CVE-2024-28986

“While it was reported as an unauthenticated vulnerability, SolarWinds has been unable to reproduce it without authentication after thorough testing. However, out of an abundance of caution, we recommend all Web Help Desk customers apply the patch, which is now available,” the company advises.

About CVE-2024-28986

SolarWinds Web Help Desk is a web-based IT help desk solution popular with SMBs, enterprises and managed service providers.

It can be integrated with Active Directory and LDAP, it centralizes and automates ticketing management, provides a centralized knowledge base, allows tracking and managing of IT assets, and more.

CVE-2024-28986 is a Java deserialization vulnerability, a type of security weakness that is among the most common vulnerabilites in Java applications. It allows attackers to inject malicious code into an application’s memory.

CVE-2024-28986 has been privately disclosed by security researchers and fixed with their help. There is no mention of it being under active exploitation.

The vulnerability affects WHD versions 12.4 through 12.8.

What to do?

SolarWinds instructs customers to immediately upgrade their installations to version 12.8.3, apply the provided hotfix – Web Help Desk 12.8.3 Hotfix 1 – and install it.

The latter step is not the last, because they will also have to copy-paste some files and manually modify a file, but luckily SolarWinds explains the who procedure clearly in the security advisory, as well as offers instructions on how to uninstall the hotfix (if needed).

While SolarWinds strongly recommends that customers install Web Help Desk on a server that is protected from unauthorized access by the public and is not internet-facing, there are surely some (hopefully not many) customers who have ignored the advice.

Attackers may soon try to analyze the hotfix, devise an exploit, and probe vulnerable installations. If SolarWinds is correct about the authentication requirement – and there is no reason why they should not be – successful exploitation of the flaw will not be as easy as initially feared by the researchers.

UPDATE (August 16, 2024, 02:20 a.m. ET):

CISA has added the vulnerability to its Known Exploited Vulnerabilities catalog.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2024/08/15/cve-2024-28986/