QID 375935

Date Published: 2021-10-07

QID 375935: Dameware Mini Remote Control Insecure File Permissions Vulnerability

Solarwinds Dameware Remote Mini Controller is a software for assisting in remote desktop connections for helpdesk support.

CVE-2021-31217: Insecure file permissions allow local file deletion with system user access in Dameware 12.0.1.2008

Affected Version:
SolarWinds Dameware Mini Remote Control 12.0.1.2008.

QID Detection Logic(Authenticated)
QID will to find the affected version of SolarWinds Dameware through registry key from installed location.

Successful exploitation of this vulnerability may allow an attacker to delete arbitrary files from the target as SYSTEM.

  • CVSS V3 rated as Critical - 9.1 severity.
  • CVSS V2 rated as Critical - 9.4 severity.
  • Solution
    Solarwinds has released version 12.2 to address this issue.

    Please refer DameWare 12.2 Release Notes

    Vendor References

    CVEs related to QID 375935

    Software Advisories
    Advisory ID Software Component Link
    Dameware 12.2 Release Notes URL Logo www.solarwinds.com/trust-center/security-advisories/cve-2021-31217