iTnews Asia
  • Home
  • News
  • Security

SolarWinds patches three critical bugs

SolarWinds patches three critical bugs

Zero Day Initiative discovered five RCEs.

By Richard Chirgwin on Feb 19, 2024 10:13AM

SolarWinds has patched five remote code execution (RCE) vulnerabilities in its Access Rights Manager software, three of which are rated critical.

The bugs were discovered and reported by Trend Micro’s Zero Day Initiative (ZDI).

The software lets users manage and audit access to Microsoft resources like Active Directory, Azure Active Directory, Exchange, SharePoint, OneDrive, and file servers.

According to SolarWinds’ advisory, CVE-2023-40057 is a bug in how the software handles deserialisation of untrusted data.

“If exploited, this vulnerability allows an authenticated user to abuse a SolarWinds service resulting in remote code execution,” the advisory said.

The other two critical bugs are CVE-2024-23476 and CVE-2024-23479. Both are directory traversal bugs, and are exploitable by unauthenticated attackers.

Two more bugs reported through ZDI, with a “high” severity rating, are CVE-2024-23477 (a directory traversal bug) and CVE-2024-23478 (a deserialisation bug).

The vulnerabilities are patched in Access Rights Manager 2023.2.3.

In a separate advisory, SolarWinds also disclosed two high-rated bugs in its Orion Platform, also discovered by ZDI.

CVE-2023-50395 and CVE-2023-35188 are both SQL injection bugs affecting an update statement and a create statement, respectively.

SolarWinds said the two bugs can only be exploited by an authenticated user, and consequently have not been seen in the wild.

Access Rights Manager last needed patching against RCEs in October last year.

SolarWinds famously suffered a major attack in 2020, reaching high-profile customers such as Microsoft.

To reach the editorial team on your feedback, story ideas and pitches, contact them here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
security solarwinds

Related Articles

  • Malicious AI inputs are creating a new and critical security threat
  • Beware the pitfalls of using a ‘DIY security’ approach
  • AI transforms cyberattacks, but human trust remains the weakest link
  • How severe will ransomware attacks become in 2026?
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Malicious AI inputs are creating a new and critical security threat

Malicious AI inputs are creating a new and critical security threat

Singapore issues advisory for FIs to mitigate quantum computing risks

Singapore issues advisory for FIs to mitigate quantum computing risks

PhilHealth estimates 13 to 20 million members affected by data breach

PhilHealth estimates 13 to 20 million members affected by data breach

Malaysia's Maxis Berhad investigates claims on alleged data breach

Malaysia's Maxis Berhad investigates claims on alleged data breach

All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of Lighthouse Independent Media's Privacy Policy and Terms & Conditions.