SolarWinds Web Help Desk
cpe:2.3:a:solarwinds:web_help_desk:*:*:*:*:*:*:*, +1 more
- <= 12.8.3 HF2
This vulnerability is being actively exploited in the wild.
A remote code execution vulnerability has been identified in SolarWinds Web Help Desk versions 12.8.3 HF2 and prior. This issue arises from Java deserialization, allowing attackers to execute commands on the host machine. The vulnerability was discovered by the Zero Day Initiative (ZDI) team, who found that it could be exploited without authentication.
Exploitation of this vulnerability allows for remote code execution on the host machine.
Users are advised to upgrade to SolarWinds Web Help Desk version 12.8.3 HF3, which includes the necessary patch.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.