First published: Mon Feb 16 2015(Updated: )
The factory.loadExtensionFactory function in TSUnicodeGraphEditorControl in SolarWinds Server and Application Monitor (SAM) allow remote attackers to execute arbitrary code via a UNC path to a crafted binary.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SolarWinds Server and Application Monitor |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-1501 is rated as critical due to the ability for remote attackers to execute arbitrary code.
To mitigate CVE-2015-1501, apply the latest patches provided by SolarWinds for the Server and Application Monitor.
CVE-2015-1501 enables attackers to exploit a vulnerability that allows execution of arbitrary code via a crafted UNC path.
CVE-2015-1501 affects all versions of SolarWinds Server and Application Monitor prior to the patch release.
You can confirm vulnerability to CVE-2015-1501 by checking the version of SolarWinds Server and Application Monitor you are using against the published advisory.