QID 379089
Date Published: 2023-12-04
QID 379089: SolarWinds Platform Remote Code Execution (RCE) Vulnerability
SolarWinds Platform is an IT performance monitoring platform.
Affected Products:
SolarWinds Platform all version prior to 2023.4.2
QID Detection Logic (Authenticated):
1. The QID extracts Solarwinds Platform version from registry key "HKLM\SOFTWARE\SolarWinds\Orion\Core or HKLM\SOFTWARE\Wow6432Node\SolarWinds\Orion\Core", value "InstallPath", then compare file version of "SolarWinds.Orion.Core.Common.dll; with patched versions
2. The QID extracts Solarwinds Platform version from registry key "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall or HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall", value "InstallLocation", then compare file version of "SolarWinds.Orion.Core.Common.dll; with patched versions
Attacker could successfully execute a code remotely on exploitation of this vulnerability
Customers are advised to refer to cve-2023-40056
CVEs related to QID 379089
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cve-2023-40056 |
|