Vulnerability record · CVE-2016-2345 · published 17 March 2016
CVE-2016-2345: SolarWinds DameWare Mini Remote Control dwrcs.exe stack buffer overflow
Dameware · Mini Remote Control
The dwmrcs daemon in SolarWinds DameWare Mini Remote Control 12.0 contains a stack-based buffer overflow in dwrcs.exe that is triggered by a crafted string. Because the flaw is remotely reachable with no authentication or user interaction, it can lead to arbitrary code execution on the affected host.
Description
Stack-based buffer overflow in dwrcs.exe in the dwmrcs daemon in SolarWinds DameWare Mini Remote Control 12.0 allows remote attackers to execute arbitrary code via a crafted string.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 3.0 base score is 9.8 with network reachability, no authentication and no user interaction, and EPSS is in the 98.9th percentile.
What it is
The dwmrcs daemon in SolarWinds DameWare Mini Remote Control 12.0 contains a stack-based buffer overflow in dwrcs.exe that is triggered by a crafted string. Because the flaw is remotely reachable with no authentication or user interaction, it can lead to arbitrary code execution on the affected host.
Impact
A remote attacker can execute arbitrary code in the context of the dwmrcs service, which typically runs with elevated privileges on the managed endpoint. Successful exploitation gives full control of the host, including confidentiality, integrity and availability impact.
Attack surface
The flaw is reached over the network through the dwmrcs daemon listening on the DameWare Mini Remote Control service port. The CVSS vector indicates no privileges and no user interaction are required, so any host that can reach the service can attempt exploitation.
Exploitation
The record is not listed in CISA KEV and no ransomware usage is documented, but EPSS is high at roughly 0.51 (98.9th percentile), indicating elevated likelihood of exploitation activity. Reference tags are limited to third-party and US Government advisories, with no explicit exploit tag.
What to do
- Upgrade SolarWinds DameWare Mini Remote Control from 12.0 to a fixed release as soon as possible.
- Restrict network access to the dwmrcs service port to trusted management hosts only.
- Place the service behind a firewall or VPN and avoid exposing it to the internet.
- Monitor vendor advisories and apply any subsequent patches for the DameWare MRC daemon.
- If the service is not required, disable or uninstall it to remove the attack surface.
Detection
- Monitor for crashes or abnormal termination of dwrcs.exe on managed endpoints.
- Inspect network traffic to the DameWare MRC service port for oversized or malformed strings.
- Review host logs for unexpected child processes spawned by dwrcs.exe.
- Alert on new outbound connections or process creation originating from the dwmrcs service account.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2016-2345 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-2345), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.