QID 375739
QID 375739: SolarWinds Server and Application Monitor Privilege Escalation Vulnerability
SolarWinds Server and Application Monitor provide monitoring, alerting, reporting, and server management options while supporting multiple hardware vendors.
Affected Product:
SolarWinds Server and Application Monitor 2020.2 versions prior to 2020.2.5
QID Detection Logic:(Authenticated)
This QID checks for APMServiceControl.exe file version to detect the vulnerable version of the product.
An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM.
Solution
SolarWinds has released fixes in version SAM 2020.2.5
Vendor References
- SAM 2020.2.5 Release Notes -
documentation.solarwinds.com/en/success_center/sam/content/release_notes/sam_2020-2-5_release_notes.htm
CVEs related to QID 375739
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SAM 2020.2.5 |
|