SolarWinds Releases Patches for High-Severity Vulnerabilities in Access Rights Manager (ARM)

SolarWinds, a leading provider of IT management software, has recently addressed eight high-severity vulnerabilities in its Access Rights Manager (ARM). Notably, this release includes patches for three remote code execution (RCE) flaws that can be exploited without authentication. These vulnerabilities were identified by Sina Kheirkhah of the Summoning Team and reported to ZDI, a leading vulnerability research organization.

Identification and Reporting of Remote Code Execution Flaws

The three RCE flaws, tracked as CVE-2023-35182, CVE-2023-35185, and CVE-2023-35187, have been disclosed by SolarWinds. These vulnerabilities were brought to the attention of SolarWinds by Sina Kheirkhah, who reported them to ZDI. These vulnerabilities are particularly concerning as they allow remote, unauthenticated attackers to execute arbitrary code with system privileges.

Exploitation and Potential Impact

The ability for attackers to execute arbitrary code with system privileges is alarming. Exploiting these vulnerabilities can lead to unauthorized access, data breaches, and further compromise of the targeted systems. This potential impact emphasizes the urgency of patching and updating the affected systems.

Severity Assessment and CVSS Scores

While SolarWinds labels these vulnerabilities as high-severity with a Common Vulnerability Scoring System (CVSS) score of 8.8, ZDI classifies them as critical with a CVSS score of 9.8. This disparity in severity assessment underscores the critical nature of these vulnerabilities and emphasizes the need for immediate action.

Lack of Proper Validation of User-Supplied Data

Among the identified vulnerabilities, one flaw stands out as a high-severity issue related to the lack of proper validation of user-supplied data in the ExecuteAction method. Tracked as CVE-2023-35184 with a CVSS score of 8.8, this vulnerability can also be exploited without authentication, further increasing its potential impact.

SolarWinds acknowledges two additional RCE vulnerabilities addressed in the Access Rights Manager update. However, authentication is required to exploit these vulnerabilities, mitigating their potential impact to some extent.

Explanation of the Bug’s Existence

The root cause behind these vulnerabilities lies in incorrect permissions set for files and folders created by the Access Rights Manager installer. These improper permissions inadvertently create opportunities for attackers to exploit the system.

Patching and Mitigation

To address these vulnerabilities, SolarWinds has promptly released Access Rights Manager 2023.2.1, which includes comprehensive patches for all identified flaws. Users are strongly urged to update their software immediately to ensure protection against potential exploitation.

Lack of Evidence of Exploitation

While SolarWinds has diligently addressed these vulnerabilities, there is no evidence thus far of any active exploitation. However, the absence of reported incidents does not diminish the importance of promptly patching and keeping software up-to-date.

SolarWinds’ swift response in releasing patches for the identified vulnerabilities in Access Rights Manager demonstrates its commitment to addressing potential security risks. The criticality of these vulnerabilities, as highlighted by ZDI, reinforces the need for users to update their software without delay. Ensuring the security of IT management systems is crucial in safeguarding sensitive data and preventing unauthorized access. By staying vigilant and proactive in patching and maintaining software, organizations can reduce the risk of compromise and enhance their overall cybersecurity posture.

Explore more

AI-Curated Inboxes Are Transforming B2B Email Strategy

The era of direct-to-human email communication has been superseded by an ecosystem where artificial intelligence serves as the primary curator and gatekeeper for all professional correspondence. In this environment, the standard metric of a successful campaign is no longer a simple open rate but rather the ability to satisfy the relevance requirements of automated agents within platforms like Google Workspace

Why Your Content Strategy Fails and How to Fix It

The digital landscape in 2026 is characterized by a relentless surge in automated content production that has fundamentally altered how audiences interact with online information. Many enterprises struggle to maintain relevance because their underlying strategies rely on outdated metrics from previous years rather than real-time behavioral signals. This lack of strategic alignment often results in a massive expenditure of resources

Which WhatsApp CRM Platform Leads the Market in 2026?

The rapid transformation of WhatsApp from a basic peer-to-peer messaging application into the backbone of international commerce has fundamentally altered how brands engage with their customer bases in 2026. While the initial era of digital communication relied heavily on email and static web forms, the current landscape demands instantaneous, personalized interactions that occur within the same interface where users speak

OpenAI Tests ChatGPT Agents to Replace Ad Landing Pages

Digital advertising has reached a point of diminishing returns where users frequently abandon traditional landing pages due to slow load times and confusing navigation menus. This friction results in billions of dollars in lost revenue annually as consumers lose interest during the critical seconds between clicking an advertisement and finding the actual product information. OpenAI is currently testing a transformative

Trend Analysis: Data Center Resource Sustainability

Behind the polished glass of modern smartphones and the seamless logic of artificial intelligence lies a massive, thirsty network of hardware that is currently pushing regional utility grids to the edge of collapse. This digital wall represents a collision where the virtual cloud meets the physical limits of water and energy availability. As artificial intelligence and cloud services expand at