SolarWinds Releases Patches for High-Severity Vulnerabilities in Access Rights Manager (ARM)

SolarWinds, a leading provider of IT management software, has recently addressed eight high-severity vulnerabilities in its Access Rights Manager (ARM). Notably, this release includes patches for three remote code execution (RCE) flaws that can be exploited without authentication. These vulnerabilities were identified by Sina Kheirkhah of the Summoning Team and reported to ZDI, a leading vulnerability research organization.

Identification and Reporting of Remote Code Execution Flaws

The three RCE flaws, tracked as CVE-2023-35182, CVE-2023-35185, and CVE-2023-35187, have been disclosed by SolarWinds. These vulnerabilities were brought to the attention of SolarWinds by Sina Kheirkhah, who reported them to ZDI. These vulnerabilities are particularly concerning as they allow remote, unauthenticated attackers to execute arbitrary code with system privileges.

Exploitation and Potential Impact

The ability for attackers to execute arbitrary code with system privileges is alarming. Exploiting these vulnerabilities can lead to unauthorized access, data breaches, and further compromise of the targeted systems. This potential impact emphasizes the urgency of patching and updating the affected systems.

Severity Assessment and CVSS Scores

While SolarWinds labels these vulnerabilities as high-severity with a Common Vulnerability Scoring System (CVSS) score of 8.8, ZDI classifies them as critical with a CVSS score of 9.8. This disparity in severity assessment underscores the critical nature of these vulnerabilities and emphasizes the need for immediate action.

Lack of Proper Validation of User-Supplied Data

Among the identified vulnerabilities, one flaw stands out as a high-severity issue related to the lack of proper validation of user-supplied data in the ExecuteAction method. Tracked as CVE-2023-35184 with a CVSS score of 8.8, this vulnerability can also be exploited without authentication, further increasing its potential impact.

SolarWinds acknowledges two additional RCE vulnerabilities addressed in the Access Rights Manager update. However, authentication is required to exploit these vulnerabilities, mitigating their potential impact to some extent.

Explanation of the Bug’s Existence

The root cause behind these vulnerabilities lies in incorrect permissions set for files and folders created by the Access Rights Manager installer. These improper permissions inadvertently create opportunities for attackers to exploit the system.

Patching and Mitigation

To address these vulnerabilities, SolarWinds has promptly released Access Rights Manager 2023.2.1, which includes comprehensive patches for all identified flaws. Users are strongly urged to update their software immediately to ensure protection against potential exploitation.

Lack of Evidence of Exploitation

While SolarWinds has diligently addressed these vulnerabilities, there is no evidence thus far of any active exploitation. However, the absence of reported incidents does not diminish the importance of promptly patching and keeping software up-to-date.

SolarWinds’ swift response in releasing patches for the identified vulnerabilities in Access Rights Manager demonstrates its commitment to addressing potential security risks. The criticality of these vulnerabilities, as highlighted by ZDI, reinforces the need for users to update their software without delay. Ensuring the security of IT management systems is crucial in safeguarding sensitive data and preventing unauthorized access. By staying vigilant and proactive in patching and maintaining software, organizations can reduce the risk of compromise and enhance their overall cybersecurity posture.

Explore more

Standardized Developer Environments Still Break DevOps Workflows

The long-standing engineering dream of achieving absolute environment parity has often remained an elusive target, despite the sophisticated containerization tools available to modern teams. For years, the industry has chased the promise of a setup so consistent that a developer could transition from a local laptop to a cloud-based server without changing a single line of configuration. While 2026 has

Retailers Use ERP, SCM, and CRM to Drive Growth in 2026

Modern supply chain management systems go beyond simple inventory tracking by using operational data to forecast demand and redistribute stock across multiple channels. This evolution represents a fundamental shift in how the retail industry operates, where the sheer volume of digital transactions and global logistics has reached unprecedented levels of complexity. As high-growth brands navigate the current landscape, the reliance

Morph Launches Non-Custodial Global Payment Gateway

For globally distributed teams, the delay of several business days required for traditional wire transfers to clear represents a substantial hurdle to efficient payroll and operations. This pervasive friction has paved the way for the introduction of Morph Payments, a decentralized gateway designed specifically to leverage the high throughput and low cost of the Morph Ethereum Layer 2 scaling network.

Is Ethereum Finally Adopting Cardano’s UTXO Model?

Algorand Foundation ambassador Lily Brodi recently noted that Ethereum’s newest scaling explorations essentially mirror the technical state Cardano has operated in for several years. This observation highlights a significant pivot in the ongoing evolution of decentralized ledgers, where the rigid distinction between account-based and Unspent Transaction Output (UTXO) models is beginning to blur. For years, the blockchain community viewed these

How Do You Measure the Success of Your Onboarding Program?

While many HR departments prioritize the delivery of administrative paperwork, only twelve percent of employees report that their organization provides a high-quality onboarding experience. This disconnect suggests that most companies view the arrival of new talent as a logistical hurdle rather than a long-term investment. Organizations often excel at the technicalities of the hiring process, such as distributing hardware, establishing