ZDI-23-169: SolarWinds Network Performance Monitor WorkerProcessWCFProxy Deserialization of Untrusted Data Remote Code Execution Vulnerability
Published Feb 24, 2023
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Network Performance Monitor. Authentication is required to exploit this vulnerability.
Affected Software
1 affected component
SolarWinds Network Performance Monitor
Event History
Feb 24, 2023
Advisory Published
06:00 AM
Data Sourced
06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-23-169?
The severity of ZDI-23-169 is high due to its potential for remote code execution.
2
How do I fix ZDI-23-169?
To fix ZDI-23-169, ensure that you apply the latest security patches provided by SolarWinds for the Network Performance Monitor.
3
What types of systems are affected by ZDI-23-169?
ZDI-23-169 affects installations of SolarWinds Network Performance Monitor that require authentication.
4
What is the impact of exploiting ZDI-23-169?
Exploiting ZDI-23-169 allows remote attackers to execute arbitrary code on the targeted system.
5
Is authentication required to exploit ZDI-23-169?
Yes, authentication is required to exploit ZDI-23-169.