SolarWinds Web Help Desk
cpe:2.3:a:solarwinds:web_help_desk:*:*:*:*:*:*:*, +1 more
- 12.8.7
This vulnerability is being actively exploited in the wild.
A remote code execution vulnerability has been identified in SolarWinds Web Help Desk versions through 12.8.7 Hotfix 1. This vulnerability arises from unauthenticated deserialization of untrusted data by the AjaxProxy, allowing attackers to execute commands on the host machine. Notably, this issue represents a patch bypass of CVE-2024-28988, which itself bypasses CVE-2024-28986.
Exploitation of this vulnerability allows for remote code execution on the host machine.
Users can upgrade to SolarWinds Web Help Desk 12.8.7 Hotfix 1, available through the SolarWinds Customer Portal. Instructions for installing this hotfix are included in the Web Help Desk 12.8.7 Hotfix 1 Administrator Guide.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.