SolarWinds Releases Patches for High-Severity Vulnerabilities in Access Rights Manager (ARM)

SolarWinds, a leading provider of IT management software, has recently addressed eight high-severity vulnerabilities in its Access Rights Manager (ARM). Notably, this release includes patches for three remote code execution (RCE) flaws that can be exploited without authentication. These vulnerabilities were identified by Sina Kheirkhah of the Summoning Team and reported to ZDI, a leading vulnerability research organization.

Identification and Reporting of Remote Code Execution Flaws

The three RCE flaws, tracked as CVE-2023-35182, CVE-2023-35185, and CVE-2023-35187, have been disclosed by SolarWinds. These vulnerabilities were brought to the attention of SolarWinds by Sina Kheirkhah, who reported them to ZDI. These vulnerabilities are particularly concerning as they allow remote, unauthenticated attackers to execute arbitrary code with system privileges.

Exploitation and Potential Impact

The ability for attackers to execute arbitrary code with system privileges is alarming. Exploiting these vulnerabilities can lead to unauthorized access, data breaches, and further compromise of the targeted systems. This potential impact emphasizes the urgency of patching and updating the affected systems.

Severity Assessment and CVSS Scores

While SolarWinds labels these vulnerabilities as high-severity with a Common Vulnerability Scoring System (CVSS) score of 8.8, ZDI classifies them as critical with a CVSS score of 9.8. This disparity in severity assessment underscores the critical nature of these vulnerabilities and emphasizes the need for immediate action.

Lack of Proper Validation of User-Supplied Data

Among the identified vulnerabilities, one flaw stands out as a high-severity issue related to the lack of proper validation of user-supplied data in the ExecuteAction method. Tracked as CVE-2023-35184 with a CVSS score of 8.8, this vulnerability can also be exploited without authentication, further increasing its potential impact.

SolarWinds acknowledges two additional RCE vulnerabilities addressed in the Access Rights Manager update. However, authentication is required to exploit these vulnerabilities, mitigating their potential impact to some extent.

Explanation of the Bug’s Existence

The root cause behind these vulnerabilities lies in incorrect permissions set for files and folders created by the Access Rights Manager installer. These improper permissions inadvertently create opportunities for attackers to exploit the system.

Patching and Mitigation

To address these vulnerabilities, SolarWinds has promptly released Access Rights Manager 2023.2.1, which includes comprehensive patches for all identified flaws. Users are strongly urged to update their software immediately to ensure protection against potential exploitation.

Lack of Evidence of Exploitation

While SolarWinds has diligently addressed these vulnerabilities, there is no evidence thus far of any active exploitation. However, the absence of reported incidents does not diminish the importance of promptly patching and keeping software up-to-date.

SolarWinds’ swift response in releasing patches for the identified vulnerabilities in Access Rights Manager demonstrates its commitment to addressing potential security risks. The criticality of these vulnerabilities, as highlighted by ZDI, reinforces the need for users to update their software without delay. Ensuring the security of IT management systems is crucial in safeguarding sensitive data and preventing unauthorized access. By staying vigilant and proactive in patching and maintaining software, organizations can reduce the risk of compromise and enhance their overall cybersecurity posture.

Explore more

ERP Systems Shift From Bolt-On to AI-Native Architecture

The traditional enterprise resource planning market has recently crossed a significant threshold where the superficial application of artificial intelligence no longer suffices for complex industrial operations. By 2026, a distinct divide has emerged between legacy platforms that merely retrofitted AI features onto old code and those built from the ground up for the modern era. This evolution is changing how

How Will XRP and Ethereum Define the 2026 Crypto Market?

The transformation of the cryptocurrency market from a speculative frontier into a foundational pillar of the global financial system has fundamentally reshaped how institutions and retail investors perceive digital assets. Today, the landscape is defined by clear regulatory frameworks and significant participation from major banking institutions, moving away from the volatility of previous cycles toward a more professionalized environment. Within

Is Workplace Abuse Behind the Climate Official’s Death?

The sudden passing of a senior director within the international climate policy framework has sent shockwaves through the scientific community and raised urgent questions about the psychological toll of high-pressure public service roles. While initial reports focused on health complications resulting from chronic stress, subsequent leaks of internal emails and whistleblower testimonies suggested a disturbing reality of systematic bullying and

Is the Future of the Linux Desktop Atomic?

The Linux desktop has undergone a radical transformation as the community moves away from the fragile, manual configuration methods of the past toward a much more resilient, image-based future. For several decades, the quintessential Linux experience was defined by a fundamental paradox where users enjoyed unparalleled control over their environment while simultaneously facing a constant risk of catastrophic system failure

Proactive Layered Strategies Neutralize Ransomware Threats

The persistent threat of digital extortion has transformed from a rare occurrence into an unavoidable reality that demands a fundamental shift in how individuals approach their computer’s security landscape. Relying solely on the hope that a system will remain unnoticed by malicious actors is no longer a viable strategy in an environment where automated exploitation tools are constantly scanning for