CISA warns critical SolarWinds RCE bug is exploited in attacks

Share:

CISA warned on Thursday that attackers are exploiting a recently patched critical vulnerability in SolarWinds’ Web Help Desk solution for customer support.

Web Help Desk (WHD) is IT help desk software widely used by large corporations, government agencies, and healthcare and education organizations worldwide to centralize, automate, and streamline help desk management tasks.

Tracked as CVE-2024-28986, this Java deserialization security flaw allows threat actors to gain remote code execution on vulnerable servers and run commands on the host machine following successful exploitation.

SolarWinds issued a hotfix for the vulnerability on Wednesday, a day before CISA’s warning. However, the company did not disclose any information about in-the-wild exploitation, although it recommended all administrators apply the fix to vulnerable devices.

“While it was reported as an unauthenticated vulnerability, SolarWinds has been unable to reproduce it without authentication after thorough testing. However, out of an abundance of caution, we recommend all Web Help Desk customers apply the patch, which is now available,” SolarWinds said.

“WHD 12.8.3 Hotfix 1 should not be applied if SAML Single Sign-On (SSO) is utilized. A new patch will be available shortly to address this problem.”

SolarWinds also published a support article with detailed instructions on applying and removing the hotfix, warning that admins must upgrade vulnerable servers to Web Help Desk 12.8.3.1813 before installing the hotfix.

The company recommends creating backups of the original files before replacing them during the installation process to avoid potential issues if the hotfix deployment fails or the hotfix isn’t applied correctly.

CISA added CVE-2024-28986 to its ts KEV catalog on Thursday, mandating federal agencies to patch their WHD servers within three weeks, until September 5, as required by the Binding Operational Directive (BOD) 22-01.

Earlier this year, SolarWinds also patched over a dozen critical remote code execution (RCE) flaws in its Access Rights Manager (ARM) software, eight in July and five in February.

In June, cybersecurity firm GreyNoise warned that threat actors were already exploiting a SolarWinds Serv-U path-traversal vulnerability, just two weeks after SolarWinds released a hotfix and days after proof-of-concept (PoC) exploits were published online.

SolarWinds says that the company’s IT management products are being used by more than 300,000 customers worldwide.

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
1:06 am, Mar 27, 2025
weather icon 7°C
L: 6° | H: 8°
few clouds
Humidity: 84 %
Pressure: 1024 mb
Wind: 5 mph SSW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 19%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 5:46 am
Sunset: 6:24 pm
DailyHourly
Daily ForecastHourly Forecast
Today 9:00 pm
weather icon
6° | 8°°C 0 mm 0% 9 mph 90 % 1024 mb 0 mm/h
Tomorrow 9:00 pm
weather icon
7° | 12°°C 1 mm 100% 13 mph 93 % 1015 mb 0 mm/h
Sat Mar 29 9:00 pm
weather icon
4° | 12°°C 0 mm 0% 9 mph 78 % 1023 mb 0 mm/h
Sun Mar 30 9:00 pm
weather icon
7° | 17°°C 0 mm 0% 10 mph 82 % 1024 mb 0 mm/h
Mon Mar 31 9:00 pm
weather icon
8° | 15°°C 0 mm 0% 8 mph 86 % 1028 mb 0 mm/h
Today 3:00 am
weather icon
8° | 9°°C 0 mm 0% 4 mph 87 % 1024 mb 0 mm/h
Today 6:00 am
weather icon
8° | 8°°C 0 mm 0% 4 mph 90 % 1023 mb 0 mm/h
Today 9:00 am
weather icon
11° | 11°°C 0 mm 0% 6 mph 69 % 1023 mb 0 mm/h
Today 12:00 pm
weather icon
16° | 16°°C 0 mm 0% 7 mph 51 % 1021 mb 0 mm/h
Today 3:00 pm
weather icon
17° | 17°°C 0 mm 0% 9 mph 47 % 1018 mb 0 mm/h
Today 6:00 pm
weather icon
15° | 15°°C 0 mm 0% 7 mph 60 % 1017 mb 0 mm/h
Today 9:00 pm
weather icon
12° | 12°°C 0 mm 0% 6 mph 78 % 1017 mb 0 mm/h
Tomorrow 12:00 am
weather icon
10° | 10°°C 0 mm 0% 7 mph 82 % 1015 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€81,401.79
-0.24%
Ethereum(ETH)
€1,882.35
-2.32%
Tether(USDT)
€0.93
-0.01%
XRP(XRP)
€2.21
-3.45%
Solana(SOL)
€128.67
-4.06%
USDC(USDC)
€0.93
0.01%
Dogecoin(DOGE)
€0.182652
1.48%
Shiba Inu(SHIB)
€0.000013
2.34%
Pepe(PEPE)
€0.000008
7.32%
Peanut the Squirrel(PNUT)
€0.214428
7.85%
Scroll to Top