CVE-2015-1501: Code Injection
The factory.loadExtensionFactory function in TSUnicodeGraphEditorControl in SolarWinds Server and Application Monitor (SAM) allow remote attackers to execute arbitrary code via a UNC path to a crafted binary.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1501?
CVE-2015-1501 is rated as critical due to the ability for remote attackers to execute arbitrary code.
How do I fix CVE-2015-1501?
To mitigate CVE-2015-1501, apply the latest patches provided by SolarWinds for the Server and Application Monitor.
What type of attack does CVE-2015-1501 facilitate?
CVE-2015-1501 enables attackers to exploit a vulnerability that allows execution of arbitrary code via a crafted UNC path.
Which software versions are affected by CVE-2015-1501?
CVE-2015-1501 affects all versions of SolarWinds Server and Application Monitor prior to the patch release.
How can I confirm if my system is vulnerable to CVE-2015-1501?
You can confirm vulnerability to CVE-2015-1501 by checking the version of SolarWinds Server and Application Monitor you are using against the published advisory.