logo

SolarWinds Access Rights Manager: One Vulnerability to LPE Them All

ID: 7bada660-95b8-5eee-8076-8428d2cf2bed

STIX ID: report--7bada660-95b8-5eee-8076-8428d2cf2bed

Feed Name: Zero Day Initiative (ZDI) Blog

Threat Score
70/100

Date Published: 2024-12-12

Date Updated: 2026-05-01

Author: Piotr Bazydło

...
...

This blog post reviews multiple security flaws in SolarWinds Access Rights Manager (ARM), focusing on pre-auth arbitrary file deletion vulnerabilities that can lead to local privilege escalation on domain-joined Windows hosts; the author also found pre-auth RCEs via .NET Remoting/gRPC, insecure deserialization enabling post-auth RCE, and file read/delete issues. The issues were addressed by SolarWinds in the ARM 2024.3 update.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.