PT-2019-6468 · Solarwinds · Dameware Mini Remote Control
Published
2019-07-11
·
Updated
2025-11-14
·
CVE-2019-3980
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
DameWare Mini Remote Control version 12.1.0.89
Description
The issue allows an unauthenticated, remote attacker to request smart card login and upload and execute an arbitrary executable run under the Local System account. This is due to a lack of source confirmation in the SmartCard Authentication component. The vulnerability has been exploited in real-world incidents, where attackers used it to load malicious software, including a Reverse Shell on Java, and a driver designed to bypass security measures and disable antivirus self-protection components. In one incident, the attackers also used QuasarRAT to establish persistence but made an error in creating a task, which prevented them from maintaining access after a system reboot.
Recommendations
For version 12.1.0.89, consider disabling the SmartCard Authentication feature until a patch is available to prevent exploitation. Restrict access to the DWRCS.exe host to minimize the risk of arbitrary executable execution. Avoid using the SmartCard Authentication component in the DameWare Mini Remote Control until the issue is resolved. As a temporary workaround, monitor system logs for suspicious activity, especially related to the execution of unknown executables or changes in system configuration.
Exploit
Fix
Origin Validation Error
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dameware Mini Remote Control