ZDI-24-1224: SolarWinds Access Rights Manager JsonSerializationBinder Deserialization of Untrusted Data Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Access Rights Manager. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The ZDI has assigned a CVSS rating of 9.9. The following CVEs are assigned: CVE-2024-28991.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-24-1224?
The severity of ZDI-24-1224 is classified as critical due to its potential to allow remote code execution.
How do I fix ZDI-24-1224?
To fix ZDI-24-1224, ensure that you apply the latest security patches released by SolarWinds for Access Rights Manager.
Who is affected by ZDI-24-1224?
Organizations using SolarWinds Access Rights Manager are affected by ZDI-24-1224.
What kind of attack does ZDI-24-1224 enable?
ZDI-24-1224 enables remote attackers to execute arbitrary code on vulnerable installations.
Is authentication required to exploit ZDI-24-1224?
Yes, while authentication is required to exploit ZDI-24-1224, it can be bypassed, making it particularly dangerous.