QID 379089

Date Published: 2023-12-04

QID 379089: SolarWinds Platform Remote Code Execution (RCE) Vulnerability

SolarWinds Platform is an IT performance monitoring platform.

Affected Products:
SolarWinds Platform all version prior to 2023.4.2

QID Detection Logic (Authenticated):
1. The QID extracts Solarwinds Platform version from registry key "HKLM\SOFTWARE\SolarWinds\Orion\Core or HKLM\SOFTWARE\Wow6432Node\SolarWinds\Orion\Core", value "InstallPath", then compare file version of "SolarWinds.Orion.Core.Common.dll; with patched versions
2. The QID extracts Solarwinds Platform version from registry key "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall or HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall", value "InstallLocation", then compare file version of "SolarWinds.Orion.Core.Common.dll; with patched versions

Attacker could successfully execute a code remotely on exploitation of this vulnerability

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 7.7 severity.
  • Solution

    Customers are advised to refer to cve-2023-40056

    CVEs related to QID 379089

    Software Advisories
    Advisory ID Software Component Link
    cve-2023-40056 URL Logo www.solarwinds.com/trust-center/security-advisories/cve-2023-40056