CISA warns critical SolarWinds RCE bug is exploited in attacks

Share:

CISA warned on Thursday that attackers are exploiting a recently patched critical vulnerability in SolarWinds’ Web Help Desk solution for customer support.

Web Help Desk (WHD) is IT help desk software widely used by large corporations, government agencies, and healthcare and education organizations worldwide to centralize, automate, and streamline help desk management tasks.

Tracked as CVE-2024-28986, this Java deserialization security flaw allows threat actors to gain remote code execution on vulnerable servers and run commands on the host machine following successful exploitation.

SolarWinds issued a hotfix for the vulnerability on Wednesday, a day before CISA’s warning. However, the company did not disclose any information about in-the-wild exploitation, although it recommended all administrators apply the fix to vulnerable devices.

“While it was reported as an unauthenticated vulnerability, SolarWinds has been unable to reproduce it without authentication after thorough testing. However, out of an abundance of caution, we recommend all Web Help Desk customers apply the patch, which is now available,” SolarWinds said.

“WHD 12.8.3 Hotfix 1 should not be applied if SAML Single Sign-On (SSO) is utilized. A new patch will be available shortly to address this problem.”

SolarWinds also published a support article with detailed instructions on applying and removing the hotfix, warning that admins must upgrade vulnerable servers to Web Help Desk 12.8.3.1813 before installing the hotfix.

The company recommends creating backups of the original files before replacing them during the installation process to avoid potential issues if the hotfix deployment fails or the hotfix isn’t applied correctly.

CISA added CVE-2024-28986 to its ts KEV catalog on Thursday, mandating federal agencies to patch their WHD servers within three weeks, until September 5, as required by the Binding Operational Directive (BOD) 22-01.

Earlier this year, SolarWinds also patched over a dozen critical remote code execution (RCE) flaws in its Access Rights Manager (ARM) software, eight in July and five in February.

In June, cybersecurity firm GreyNoise warned that threat actors were already exploiting a SolarWinds Serv-U path-traversal vulnerability, just two weeks after SolarWinds released a hotfix and days after proof-of-concept (PoC) exploits were published online.

SolarWinds says that the company’s IT management products are being used by more than 300,000 customers worldwide.

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
10:13 pm, Jan 22, 2025
weather icon 4°C
L: 2° | H: 5°
broken clouds
Humidity: 87 %
Pressure: 1003 mb
Wind: 7 mph W
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 75%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 7:52 am
Sunset: 4:31 pm
DailyHourly
Daily ForecastHourly Forecast
Tomorrow 9:00 pm
weather icon
2° | 5°°C 1 mm 100% 18 mph 89 % 1005 mb 0 mm/h
Fri Jan 24 9:00 pm
weather icon
5° | 11°°C 1 mm 100% 25 mph 89 % 1004 mb 0 mm/h
Sat Jan 25 9:00 pm
weather icon
2° | 5°°C 1 mm 100% 6 mph 96 % 1013 mb 0 mm/h
Sun Jan 26 9:00 pm
weather icon
1° | 7°°C 0 mm 0% 16 mph 95 % 1013 mb 0 mm/h
Mon Jan 27 9:00 pm
weather icon
4° | 9°°C 1 mm 100% 26 mph 92 % 996 mb 0 mm/h
Tomorrow 12:00 am
weather icon
4° | 4°°C 0 mm 0% 4 mph 84 % 1003 mb 0 mm/h
Tomorrow 3:00 am
weather icon
3° | 3°°C 0 mm 0% 5 mph 89 % 1004 mb 0 mm/h
Tomorrow 6:00 am
weather icon
3° | 3°°C 0 mm 0% 7 mph 87 % 1005 mb 0 mm/h
Tomorrow 9:00 am
weather icon
4° | 4°°C 0 mm 0% 9 mph 83 % 1004 mb 0 mm/h
Tomorrow 12:00 pm
weather icon
8° | 8°°C 0 mm 0% 16 mph 76 % 1000 mb 0 mm/h
Tomorrow 3:00 pm
weather icon
8° | 8°°C 1 mm 100% 18 mph 71 % 999 mb 0 mm/h
Tomorrow 6:00 pm
weather icon
6° | 6°°C 0.8 mm 80% 16 mph 72 % 1002 mb 0 mm/h
Tomorrow 9:00 pm
weather icon
5° | 5°°C 0 mm 0% 11 mph 75 % 1004 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€99,969.99
-2.28%
Ethereum(ETH)
€3,132.50
-2.03%
XRP(XRP)
€3.05
-0.16%
Tether(USDT)
€0.96
-0.05%
Solana(SOL)
€252.98
4.07%
Dogecoin(DOGE)
€0.345479
-4.05%
USDC(USDC)
€0.96
0.01%
Shiba Inu(SHIB)
€0.000019
-2.75%
Pepe(PEPE)
€0.000014
-3.41%
Peanut the Squirrel(PNUT)
€0.348999
-2.58%
Scroll to Top