CyberzSOC

Publication detail
← Back to advisories & guidance

2024-081: SolarWinds Web Help Desk Critical Remote Code Execution Vulnerability ↗ source

August 16, 2024 CERT-EU Advisory

Summary

The vulnerability, caused by a Java deserialization flaw, allows attackers to execute arbitrary commands on the affected system. CVE-2024-28986 is a Java deserialization vulnerability that allows attackers to execute remote commands on the vulnerable system. Initially reported as an unauthenticated exploit, it was later confirmed to require authentication for exploitation [1]. CERT-EU strongly recommends updating to the latest version (12.8.3) and applying the provided hotfix immediately.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2024-28986 9.8 Critical SolarWinds Web Help Desk SolarWinds Web Help Desk contains a deserialization of untrusted data vulnerability that could allow for remote code execution.

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.