RCE via Actions and JSON Deserialization Vulnerability
(CVE-2021-31474)
Summary
This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Network Performance Monitor 2020.2.1. Authentication is required to exploit this vulnerability. The specific flaw exists within the SolarWinds.Serialization library. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-12213.
Affected Products
- Orion Platform 2020.2.4 and earlier
Fixed Software Release
Acknowledgments
- Chudy working with Trend Micro Zero Day Initiative
Advisory Details
Severity
9.1 Critical
Advisory ID
First Published
03/25/2021
Version
Orion Platform 2020.2.5