SaveUserSetting Improper Access Control Privilege Escalation Vulnerability
(CVE-2021-27258)
Security Advisory Summary
This vulnerability allows remote attackers to execute escalate privileges on affected installations of SolarWinds Orion Platform 2020.2. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SaveUserSetting endpoint. The issue results from improper restriction of this endpoint to unprivileged users. An attacker can leverage this vulnerability to escalate privileges their privileges from Guest to Administrator. Was formerly labeled ZDI-CAN-11903.
Affected Products
- Orion Platform versions 2020.2.4 and earlier
Fixed Software Release
Acknowledgments
- Chudy working with Trend Micro Zero Day Initiative
Advisory Details
Severity
8.9 High
Advisory ID
First Published
03/25/2021
Fixed Version
Orion Platform 2020.2.4