Vulnerability record · CVE-2022-38111 · published 15 February 2023
CVE-2022-38111: SolarWinds Platform deserialization allows command execution
Solarwinds · Orion Platform
SolarWinds Platform (Orion Platform) is vulnerable to deserialization of untrusted data, which lets an attacker run arbitrary commands on the host. The flaw requires an Orion admin-level account on the Web Console, so it is a post-authentication escalation path rather than an unauthenticated entry point.
Description
SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 7.2 with high confidentiality, integrity and availability impact, and a very high EPSS score, though exploitation requires admin credentials.
What it is
SolarWinds Platform (Orion Platform) is vulnerable to deserialization of untrusted data, which lets an attacker run arbitrary commands on the host. The flaw requires an Orion admin-level account on the Web Console, so it is a post-authentication escalation path rather than an unauthenticated entry point.
Impact
An attacker with Orion admin access can execute arbitrary commands on the SolarWinds server, gaining control of the monitoring host and potentially pivoting to systems it manages.
Attack surface
Reached over the network through the SolarWinds Web Console (AV:N, AC:L, PR:H, UI:N). Exploitation requires a valid Orion admin-level account; no user interaction is needed.
Exploitation
Not listed in CISA KEV and no public exploit references are provided, but EPSS is very high (0.848, ~99.7th percentile), indicating elevated predicted exploitation activity.
What to do
- Apply the SolarWinds Platform 2023.1 release or later, which the vendor advisory and release notes address.
- Restrict and audit Orion admin accounts; enforce least privilege and remove unused admin access.
- Limit network exposure of the SolarWinds Web Console to trusted management networks.
- Monitor and alert on unexpected process execution or command activity originating from the SolarWinds server.
Detection
- Monitor SolarWinds server logs for anomalous deserialization errors or unexpected object handling.
- Alert on child processes spawned by the SolarWinds Web Console or Orion services.
- Track Orion admin account logins and changes, especially outside normal maintenance windows.
- Correlate outbound connections from the SolarWinds host to unusual destinations.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2022-38111 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-38111), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.