logo

SolarWinds fixes critical RCE bugs in access rights audit solution

ID: f8279a06-c2db-57ef-9ff1-9616d9698aea

STIX ID: report--f8279a06-c2db-57ef-9ff1-9616d9698aea

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-02-16

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

SolarWinds released patches for five remote code execution vulnerabilities in Access Rights Manager—three rated critical (including CVE-2023-40057, CVE-2024-23476, CVE-2024-23479) and two high—rooted in path traversal and deserialization flaws that permit unauthenticated code execution on unpatched systems; fixes are included in ARM 2023.2.3, most issues were reported through Trend Micro’s ZDI, and SolarWinds reports no known active exploitation. The report also recalls the March 2020 SolarWinds supply-chain compromise (APT29) to highlight potential supply-chain risk context.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.