SolarWinds Access Rights Manager: Attackers with system rights & malicious code
The developers have closed eight critical security vulnerabilities in SolarWinds ARM.
(Image: Artur Szczybylo/Shutterstock.com)
Attackers can exploit several software vulnerabilities in Access Rights Manager (ARM) from SolarWinds and compromise PCs. A version including a security patch is available for download.
Critical security vulnerabilities closed
Admins use ARM to manage access authorizations. In many cases, attackers must be logged in to systems in order to exploit one of the vulnerabilities and execute malicious code (e.g. CVE-2024-23471 "critical"). In other places, however, this should also work without authentication (CVE-2024-23467 "critical").
Videos by heise
Attacks are also possible without logging in, after which attackers have system rights (CVE-2024-23466 "critical"). In both cases, successfully attacked systems are usually considered fully compromised.
How attacks can proceed in detail remains unclear. The vulnerabilities were discovered by Trend Micro's Zero Day Initiative. The developers claim to have closed the gaps in version ARM 2024.3. All previous versions are said to be vulnerable.
List sorted by threat level in descending order:
- CreateFile Directory Traversal Remote Code Execution Vulnerability (CVE-2024-23471)
- UserScriptHumster Exposed Dangerous Method Remote Command Execution Vulnerability (CVE-2024-23470)
- Directory Traversal Remote Code Execution Vulnerability (CVE-2024-23466)
- Traversal Remote Code Execution Vulnerability (CVE-2024-23467)
- Exposed Dangerous Method Remote Code Execution Vulnerability (CVE-2024-23469)
- Internal Deserialization Remote Code Execution Vulnerability (CVE-2024-28074)
- Directory Traversal Arbitrary File Deletion and Information Disclosure Vulnerability (CVE-2024-23472)
- Traversal and Information Disclosure Vulnerability (CVE-2024-23475)
- ChangeHumster Exposed Dangerous Method Authentication Bypass Vulnerability (CVE-2024-23465)
- Traversal and Information Disclosure Vulnerability (CVE-2024-28992)
- Traversal and Information Disclosure Vulnerability (CVE-2024-23468)
- DeleteTransferFile Directory Traversal Arbitrary File Deletion and Information Disclosure Vulnerability (CVE-2024-23474)
(des)