SolarWinds Platform Local Privilege Escalation Vulnerability 

(CVE-2022-47505)

Summary

The SolarWinds Platform was susceptible to the Local Privilege Escalation Vulnerability. This vulnerability allows a local adversary with a valid system user account to escalate local privileges.

Affected Products

  • SolarWinds Platform 2023.1 and earlier

Fixed Software Release

  • SolarWinds Platform 2023.2

Acknowledgments

  • Piotr Bazydlo (@chudypb) of Trend Micro Zero Day Initiative

Workarounds

SolarWinds recommends customers upgrade to SolarWinds Platform version 2023.2 as soon as it becomes available. The expected release is by the end of April 2023. SolarWinds also recommends customers to follow the guidance provided in the SolarWinds Secure Configuration Guide. Ensure only authorized users can access the SolarWinds Platform. Special attention should be given to the following points from the documentation:

Advisory Details

Severity

7.8 High

Advisory ID

First Published

04/18/2023

Last Updated

04/18/2023

Fixed Version

SolarWinds Platform 2023.2