SaveUserSetting Improper Access Control Privilege Escalation Vulnerability (CVE-2021-27258)

Security Advisory Summary

This vulnerability allows remote attackers to execute escalate privileges on affected installations of SolarWinds Orion Platform 2020.2. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SaveUserSetting endpoint. The issue results from improper restriction of this endpoint to unprivileged users. An attacker can leverage this vulnerability to escalate privileges their privileges from Guest to Administrator. Was formerly labeled ZDI-CAN-11903.

Affected Products

  • Orion Platform versions 2020.2.4 and earlier

Fixed Software Release

Acknowledgments

  • Chudy working with Trend Micro Zero Day Initiative
Advisory Details
Severity
High
Advisory ID
First Published
03/25/2021
Fixed Version

Orion Platform 2020.2.4

CVSS Score
Download PDF
Send an Email