Target Industry

Indiscriminate, opportunistic targeting.

Overview

A remote code execution (RCE) has been disclosed within SolarWinds Web Help Desk, tracked as CVE-2024-28986 (CVSS 9.8) that could allow attackers to run commands on the host machine. SolarWinds has released a hotfix that addressed the flaw, but authentication is required for successful exploitation.

Impact

Successful exploitation of CVE-2024-28986 would allow an attacker to run commands on the host machine.

Vulnerability Detection

A security patch has been released by SolarWinds with regards to the disclosed vulnerability. As such, previous product versions remain vulnerable to potential exploitation.

Affected Products

SolarWinds Web Help Desk (WHD) 12.8.3 and all previous versions.

Containment, Mitigations & Remediations

We strongly recommend that users of affected SolarWinds systems apply the SolarWinds Web Help Desk (WHD) 12.8.3 HF2 update as soon as possible.

Indicators of Compromise

No indicators of compromise (IoCs) are available currently.

Threat Landscape

SolarWinds occupies a significant portion of the IT management market share. The platform is used extensively within corporate networks across the industry sector spectrum. The Web Help Desk is widely utilised by large businesses, banks, and governments and is used to track and manage IT assets. Due to the wide adoption of this platform within many industries, successful exploitation of this vulnerability will likely have an impact on supply chains.

The Russian nation state-sponsored threat actor group, tracked as Midnight Blizzard, targeted SolarWinds in 2020 by deploying malicious code into the Orion IT monitoring and management software in a supply-chain compromise. Having been previously subjected to malicious cyber operations, it is therefore of critical importance to adhere to the recommended remediation and mitigation strategies to reduce the risk of exploitation.

Threat Group

No attribution to specific threat actors or groups has been identified at the time of writing.

Mitre Methodologies

CWE-502: Deserialization of Untrusted Data

Further Information

SolarWinds Trust Center Security Advisory

Intelligence Terminology Yardstick

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content