cascentric.blogg.se

Solarwinds dameware vulnerability
Solarwinds dameware vulnerability




solarwinds dameware vulnerability

The manipulation with an unknown input leads to a privilege escalation vulnerability. Using CWE to declare the problem leads to CWE-275. In SolarWinds DameWare Mini Remote Control Server 12.0.1.200, insecure file permissions allow file deletion as SYSTEM. The identification of this vulnerability is CVE-2021-31217 since. The requirement for exploitation is a simple authentication. The technical details are unknown and an exploit is not publicly available. The pricing for an exploit might be around USD $0-$5k at the moment ( estimation calculated on ). The attack technique deployed by this issue is T1222 according to MITRE ATT&CK. There is no information about possible countermeasures known.






Solarwinds dameware vulnerability