SaveUserSetting Improper Access Control Privilege Escalation Vulnerability 

(CVE-2021-27258)

Security Advisory Summary

This vulnerability allows remote attackers to execute escalate privileges on affected installations of SolarWinds Orion Platform 2020.2. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SaveUserSetting endpoint. The issue results from improper restriction of this endpoint to unprivileged users. An attacker can leverage this vulnerability to escalate privileges their privileges from Guest to Administrator. Was formerly labeled ZDI-CAN-11903.

Affected Products

  • Orion Platform versions 2020.2.4 and earlier

Fixed Software Release

Acknowledgments

  • Chudy working with Trend Micro Zero Day Initiative

Advisory Details

Severity

8.9 High

Advisory ID

First Published

03/25/2021

Fixed Version

Orion Platform 2020.2.4