ZDI-23-213: SolarWinds Network Performance Monitor WorkerControllerWCFProxy Deserialization of Untrusted Data Remote Code Execution Vulnerability
Published Mar 7, 2023
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Network Performance Monitor. Authentication is required to exploit this vulnerability.
Affected Software
1 affected component
SolarWinds Network Performance Monitor
Event History
Mar 7, 2023
Advisory Published
06:00 AM
Data Sourced
06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-23-213?
The severity of ZDI-23-213 is critical due to its potential for remote arbitrary code execution.
2
How do I fix ZDI-23-213?
To fix ZDI-23-213, apply the latest security patch provided by SolarWinds for Network Performance Monitor.
3
What software is affected by ZDI-23-213?
ZDI-23-213 affects SolarWinds Network Performance Monitor installations that allow unauthenticated access.
4
What attacker capabilities are involved in ZDI-23-213?
ZDI-23-213 allows remote authenticated attackers to execute arbitrary code on the affected system.
5
Is authentication required to exploit ZDI-23-213?
Yes, authentication is required to exploit the ZDI-23-213 vulnerability.