SolarWinds has released security updates to address four vulnerabilities affecting the company's Orion IT platform, two of which allow attackers to remotely execute arbitrary code.
The Orion platform is an IT administration service that allows corporate organizations to manage, optimize and monitor their IT infrastructures (SaaS).

Fixes for critical and high severity vulnerabilities
The high-severity security flaw patched by SolarWinds on Thursday is a critical JSON deserialization bug that remote attackers can exploit to execute arbitrary code via Orion Platform Action Manager test alerts.
See also: USA: SolarWinds hackers "hit" NASA and FAA!
Fortunately, despite being rated as a critical flaw by SolarWinds, only certified users can successfully exploit it.
A second RCE vulnerability was rated as high severity because it could be used by attackers to execute arbitrary code remotely. However, this flaw also requires attackers to know the credentials of a non-privileged local account on the targeted Orion Server.
See also: Microsoft reveals 3 more malware strains used by SolarWinds hackers
The two vulnerabilities, reported through Trend Micro's Zero Day Initiative, have not yet been assigned CVE numbers.
SolarWinds has also included several security enhancements in this new version of the Orion Platform.
Administrators can deploy security updates and additional security enhancements by installing Orion Platform version 2020.2.5.
“If you are upgrading from Orion Platform 2015.1.3 or later, use the SolarWinds Orion Installer to simultaneously upgrade your entire Orion deployment to the current versions,” SolarWinds explained.
See also: SolarWinds: Supernova malware linked to Chinese group Spiral
Administrators upgrading from an Orion Platform 2019.2 installation or later do not need to download the Orion Installer first. They can upgrade their entire Orion deployment by going to the My Orion Deployment page and going to Settings > My Orion Deployment > Updates & Evaluations.
SolarWinds last month patched three other critical vulnerabilities, one of which allowed remote attackers to take control of Orion servers.
Information source: bleepingcomputer.com
