SolarWinds Web Help Desk Exploited for RCE in Multi-Stage Attacks on Exposed Servers
ID: a5a3d230-7570-5848-82d7-39fb34129741
STIX ID: report--a5a3d230-7570-5848-82d7-39fb34129741
Feed Name: The Hacker News
Microsoft observed active exploitation of internet-exposed SolarWinds Web Help Desk (WHD) instances using high-severity vulnerabilities (including CVE-2025-40551 and others) to achieve unauthenticated RCE. Attackers used PowerShell and BITS to download payloads, installed legitimate RMM components for persistence, performed DLL side‑loading to dump LSASS and steal credentials, and executed DCSync and lateral movement to target Domain Admins; CISA added CVE-2025-40551 to its KEV catalog and organizations are advised to patch, remove unauthorized RMM tools, rotate credentials, and isolate affected hosts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
