ZDI-23-166: SolarWinds Network Performance Monitor SqlFileScript Deserialization of Untrusted Data Remote Code Execution Vulnerability
Published Feb 24, 2023
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Network Performance Monitor. Authentication is required to exploit this vulnerability.
Affected Software
1 affected component
SolarWinds Network Performance Monitor
Event History
Feb 24, 2023
Advisory Published
06:00 AM
Data Sourced
06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-23-166?
The severity of ZDI-23-166 is critical due to its potential for remote code execution.
2
How do I fix ZDI-23-166?
To fix ZDI-23-166, apply the latest security updates provided by SolarWinds for the Network Performance Monitor.
3
Who is affected by ZDI-23-166?
Any user with installations of SolarWinds Network Performance Monitor that are not patched are affected by ZDI-23-166.
4
Is authentication required to exploit ZDI-23-166?
Yes, authentication is required to exploit the ZDI-23-166 vulnerability.
5
What type of attacks can ZDI-23-166 enable?
ZDI-23-166 can enable remote attackers to execute arbitrary code on affected systems.