SolarWinds fixes 8 critical bugs in access rights audit software
ID: 7f822bc7-deeb-503c-996e-65dda9d78af3
STIX ID: report--7f822bc7-deeb-503c-996e-65dda9d78af3
Feed Name: Bleeping Computer
SolarWinds released Access Rights Manager 2024.3 to patch eight critical vulnerabilities—six allowing remote code execution (CVE-2024-23469, CVE-2024-23466, CVE-2024-23467, CVE-2024-28074, CVE-2024-23471, CVE-2024-23470), plus directory traversal flaws (CVE-2024-23475, CVE-2024-23472) and an authentication bypass (CVE-2024-23465) that could enable unauthenticated domain-admin access; SolarWinds has not reported proof-of-concept exploits or active exploitation in the wild and the notice references the company’s 2020 supply-chain compromise by APT29 for context.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
