PT-2025-23511 · Solarwinds · Solarwinds Dameware Mini Remote Control

Alexander Pudwill

·

Published

2025-06-02

·

Updated

2025-06-11

·

CVE-2025-26396

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SolarWinds Dameware Mini Remote Control versions prior to 12.3.2
Description The issue is related to incorrect permissions in the SolarWinds Dameware Mini Remote Control Service, which can allow an attacker to escalate privileges locally. This vulnerability requires local access and a valid low-privilege account to be susceptible.
Recommendations For versions prior to 12.3.2, update to version 12.3.2 immediately to resolve the issue. As a temporary workaround, consider restricting access to the service to minimize the risk of exploitation.

Fix

LPE

Improper Privilege Management

Weakness Enumeration

Related Identifiers

BDU:2025-06496
CVE-2025-26396
ZDI-25-320

Affected Products

Solarwinds Dameware Mini Remote Control