SolarWinds fixed a critical RCE flaw in its Web Help Desk software
SolarWinds修复了Web Help Desk软件中的一个关键远程代码执行(RCE)漏洞(CVE-2025-26399),该漏洞允许攻击者在未认证情况下通过AjaxProxy反序列化执行任意命令。建议用户尽快安装热修复以缓解风险。 2025-9-24 11:50:45 Author: securityaffairs.com(查看原文) 阅读量:6 收藏

SolarWinds fixed a critical RCE flaw in its Web Help Desk software

Pierluigi Paganini September 24, 2025

SolarWinds fixed a critical flaw in its Web Help Desk software that could allow attackers to execute arbitrary commands on vulnerable systems.

SolarWinds has released hot fixes to address a critical flaw, tracked as CVE-2025-26399 (CVSS score: 9.8), affecting its Web Help Desk software. An attacker could exploit the flaw to execute arbitrary commands on susceptible systems.

“SolarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxProxy deserialization remote code execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine.” reads the advisory. “This vulnerability is a patch bypass of CVE-2024-28988, which in turn is a patch bypass of CVE-2024-28986.”

The vulnerability affects SolarWinds Web Help Desk 12.8.7 and all previous versions.

An anonymous researcher working with the Trend Micro Zero Day Initiative reported the flaw.

The new SolarWinds Web Help Desk flaw allows unauthenticated RCE via AjaxProxy deserialization, bypassing fixes for CVE-2024-28988 and CVE-2024-28986.

Deserialization of Untrusted Data is a high-severity vulnerability where an application reconstructs objects from data received from untrusted sources, without verifying integrity or validity. Attackers can craft malicious serialized objects that, when deserialized, abuse the logic of the application to execute code, access sensitive data, escalate privileges, or manipulate system processes. 

Currently, there is no evidence that the vulnerability is being actively exploited in attacks in the wild.

The company recommends users to install hot fixes as soon as possible

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, RCE)




文章来源: https://securityaffairs.com/182545/security/solarwinds-fixed-a-critical-rce-flaw-in-its-web-help-desk-software.html
如有侵权请联系:admin#unsafe.sh