Vulnerability record · CVE-2022-36958 · published 20 October 2022
CVE-2022-36958: SolarWinds Platform Web Console deserialization allows remote command execution
Solarwinds · Orion Platform
SolarWinds Platform (Orion Platform) deserializes untrusted data, letting an attacker run arbitrary commands. The flaw is reachable remotely through the Web Console by a user who already holds valid credentials. Because it yields full command execution on a monitoring platform, it is a serious post-authentication compromise path.
Description
SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with valid access to SolarWinds Web Console to execute arbitrary commands.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityRemote code execution with high CIA impact and a very high EPSS score, though it requires valid credentials and is not in KEV.
What it is
SolarWinds Platform (Orion Platform) deserializes untrusted data, letting an attacker run arbitrary commands. The flaw is reachable remotely through the Web Console by a user who already holds valid credentials. Because it yields full command execution on a monitoring platform, it is a serious post-authentication compromise path.
Impact
An attacker with valid Web Console access gains arbitrary command execution on the SolarWinds server, with high impact to confidentiality, integrity and availability. This can lead to full control of the platform and any data or downstream systems it manages.
Attack surface
Reached over the network via the SolarWinds Web Console (CVSS AV:N). It requires low privileges (PR:L) and no user interaction (UI:N), so any valid low-privileged account is enough.
Exploitation
Not listed in CISA KEV and no ransomware use documented. EPSS is very high (0.82746, 99.65th percentile), and references are only vendor and ZDI advisories, so no public exploit code is confirmed in this record.
What to do
- Apply the SolarWinds fix for CVE-2022-36958 from the vendor advisory as the first action.
- Restrict and audit Web Console accounts; remove unused or over-privileged accounts and enforce least privilege.
- Limit network access to the Web Console to trusted management networks rather than exposing it broadly.
- Monitor and alert on suspicious child processes spawned by SolarWinds/Orion service processes.
Detection
- Alert on unexpected child processes (cmd.exe, powershell.exe, /bin/sh) spawned by SolarWinds/Orion web or service processes.
- Review Web Console authentication logs for anomalous logins or use of low-privileged accounts.
- Hunt for deserialization-related errors or unusual HTTP POST bodies to Web Console endpoints in web and application logs.
- Baseline normal SolarWinds process behavior and flag deviations in process lineage and network egress.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.solarwinds.com/trust-center/security-advisories/CVE-2022-36958 | Vendor Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-CAN-17567 | Third Party AdvisoryVDB Entry |
| https://www.solarwinds.com/trust-center/security-advisories/CVE-2022-36958 | Vendor Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-CAN-17567 | Third Party AdvisoryVDB Entry |
Track CVE-2022-36958 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-36958), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.