SolarWinds is patching two security vulnerabilities in its Access Rights Manager (ARM) software, including a critical vulnerability that could lead to remote code execution.

The vulnerability, which is tracked as CVE-2024-28991, is a case of “deserialization of untrusted data.”
“ SolarWinds Access Rights Manager (ARM) is vulnerable to a remote code execution vulnerability ,” the company said . “If exploited, this vulnerability could allow an authorized user to abuse the service, resulting in remote code execution .”
See also: PoC exploit for critical vulnerability in Ivanti Endpoint Manager
Security researcher Piotr Bazydlo of Trend Micro Zero Day Initiative (ZDI) discovered and reported the vulnerability on May 24, 2024.
ZDI has rated the vulnerability as critical (CVSS 9.9/10) and says it exists in a class called JsonSerializationBinder and stems from a lack of proper validation of user-supplied data.
"Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed," the researcher said.
The second vulnerability that SolarWinds has patched is in Access Rights Manager (ARM), tracked as CVE-2024-28990 (CVSS score: 6.3). If successfully exploited, attackers could gain unauthorized access to the RabbitMQ management console.
See also: RCE vulnerability allows hackers to execute code on millions of servers
SolarWinds has patched both vulnerabilities with ARM version 2024.3.1. While there is currently no evidence of exploitation of the flaws, it is recommended that systems be updated immediately.

These vulnerabilities highlight the importance of regular software updates and patches security. Vulnerabilities can be exploited by cybercriminalsif not addressed promptly, potentially leading to significant damage and data breaches. Companies should regularly check for updates and apply them as soon as they become available.
See also: D-Link patches critical vulnerabilities in WiFi 6 routers
Additionally, this incident serves as a reminder that even reputable companies like SolarWinds are prone to security flaws. It is vital for organizations to have a comprehensive cybersecurityin place, including regular risk assessments and employee training on best practices for identifying and responding to potential threats.
Source: thehackernews.com
