ZDI-23-167: SolarWinds Orion Platform BytesToMessage Deserialization of Untrusted Data Remote Code Execution Vulnerability
Published Feb 24, 2023
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Orion Platform. Authentication is required to exploit this vulnerability.
Affected Software
1 affected component
SolarWinds Orion Platform
Event History
Feb 24, 2023
Advisory Published
06:00 AM
Data Sourced
06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-23-167?
The severity of ZDI-23-167 is critical due to the potential for remote code execution.
2
How do I fix ZDI-23-167?
To fix ZDI-23-167, apply the latest security updates provided by SolarWinds for the Orion Platform.
3
What impact does ZDI-23-167 have on affected systems?
ZDI-23-167 can allow authenticated remote attackers to execute arbitrary code on affected installations of SolarWinds Orion Platform.
4
Is authentication required to exploit ZDI-23-167?
Yes, authentication is required to exploit the vulnerability ZDI-23-167.
5
Which versions of SolarWinds Orion Platform are affected by ZDI-23-167?
ZDI-23-167 affects all installations of the SolarWinds Orion Platform that have not been patched.