SolarWinds fixes critical RCE bugs in access rights audit solution
ID: f8279a06-c2db-57ef-9ff1-9616d9698aea
STIX ID: report--f8279a06-c2db-57ef-9ff1-9616d9698aea
Feed Name: Bleeping Computer
SolarWinds released patches for five remote code execution vulnerabilities in Access Rights Manager—three rated critical (including CVE-2023-40057, CVE-2024-23476, CVE-2024-23479) and two high—rooted in path traversal and deserialization flaws that permit unauthenticated code execution on unpatched systems; fixes are included in ARM 2023.2.3, most issues were reported through Trend Micro’s ZDI, and SolarWinds reports no known active exploitation. The report also recalls the March 2020 SolarWinds supply-chain compromise (APT29) to highlight potential supply-chain risk context.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
