PT-2024-4876 · Solarwinds · Solarwinds Access Rights Manager

Chudypb

+1

·

Published

2024-01-12

·

Updated

2024-09-10

·

CVE-2024-23469

CVSS v3.1

9.6

Critical

VectorAV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: SolarWinds Access Rights Manager (ARM) (affected versions not specified)
Description: The issue is related to a Remote Code Execution vulnerability in the SolarWinds Access Rights Manager (ARM). If exploited, this vulnerability allows an unauthenticated user to perform actions with SYSTEM privileges. The vulnerability is associated with the use of dangerous methods or functions, specifically the EndUpdate method. Exploitation of this vulnerability may allow a remote attacker to execute arbitrary code.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Weakness Enumeration

Related Identifiers

BDU:2024-05400
CVE-2024-23469
ZDI-24-912

Affected Products

Solarwinds Access Rights Manager