QID 379033

Date Published: 2023-11-28

QID 379033: SolarWinds Platform Insecure Job Execution Mechanism Vulnerability (CVE-2023-40061)

SolarWinds Platform is an IT performance monitoring platform.

Affected Products:
SolarWinds Platform all version prior to 2023.4

QID Detection Logic (Authenticated):
1. The QID extracts Solarwinds Orion Platform version from registry key "HKLM\SOFTWARE\SolarWinds\Orion\Core or HKLM\SOFTWARE\Wow6432Node\SolarWinds\Orion\Core", value "InstallPath", then compare file version of "SolarWinds.Orion.Core.Common.dll; with patched versions
2. The QID extracts Solarwinds Orion Platform version from registry key "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall or HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall", value "InstallLocation", then compare file version of "SolarWinds.Orion.Core.Common.dll; with patched versions

On Successful exploitation of this vulnerability an attacker can execute jobs and it can lead to other attacks as a result.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Medium - 3.3 severity.
  • Solution

    Customers are advised to refer to CVE-2023-40061

    CVEs related to QID 379033

    Software Advisories
    Advisory ID Software Component Link
    CVE-2023-40061 URL Logo www.solarwinds.com/trust-center/security-advisories/cve-2023-40061