SolarWinds Security Updates – 14 August 2024

SolarWinds has released security updates to address a critical vulnerability affecting SolarWinds Web Help Desk 12.8.3 and all previous versions.

The addressed vulnerability could allow the remote attacker to execute arbitrary code, run commands on the host machine, and gain access to the affected system.

SolarWinds Web Help Desk Java Deserialization Remote Code Execution Vulnerability (CVE-2024-28986):

  • CVSS: 9.8
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Gain Access
Vulnerabilities

CVE-2024-28986

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

SolarWinds Security Updates

References