Vulnerability record · CVE-2024-28075 · published 14 May 2024
CVE-2024-28075: SolarWinds Access Rights Manager deserialization leads to remote code execution
Solarwinds · Access Rights Manager
SolarWinds Access Rights Manager contains a deserialization of untrusted data flaw (CWE-502) that lets an authenticated user abuse a SolarWinds service and achieve remote code execution. It matters because a low-privileged account can turn into code execution on a security-critical identity and access management server.
Description
The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an authenticated user to abuse SolarWinds service resulting in remote code execution. We thank Trend Micro Zero Day Initiative (ZDI) for its ongoing partnership in coordinating with SolarWinds on responsible disclosure of this and other potential vulnerabilities.
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityRemote code execution on an identity and access management server with a very high EPSS score, though exploitation requires an authenticated adjacent-network foothold.
What it is
SolarWinds Access Rights Manager contains a deserialization of untrusted data flaw (CWE-502) that lets an authenticated user abuse a SolarWinds service and achieve remote code execution. It matters because a low-privileged account can turn into code execution on a security-critical identity and access management server.
Impact
An attacker with a valid low-privileged account gains remote code execution on the Access Rights Manager host, with high impact to confidentiality, integrity and availability.
Attack surface
The flaw is reachable over an adjacent network path (CVSS AV:A) and requires authentication (PR:L) but no user interaction (UI:N). No further detail on the specific endpoint or service is given in the record.
Exploitation
Not listed in CISA KEV and no public exploit reference is tagged, but EPSS is very high at 0.78 (99.6th percentile), indicating elevated near-term exploitation likelihood.
What to do
- Upgrade Access Rights Manager to the fixed release noted in the SolarWinds advisory and 2023.2.4 release notes.
- Restrict network access to ARM services to trusted management segments, since the vector is adjacent network.
- Review and minimize accounts with access to ARM and enforce least privilege on service accounts.
- Apply the vendor hardening guidance in the 'Secure your ARM deployment' documentation.
- Monitor ARM hosts for unexpected child processes or service restarts after authenticated activity.
Detection
- Alert on unusual child processes spawned by ARM services or the ARM application pool.
- Baseline and monitor authentication to ARM, flagging new or low-privileged accounts performing administrative actions.
- Watch for deserialization-related errors or crashes in ARM service logs.
- Monitor for outbound connections from ARM hosts to unfamiliar internal or external endpoints.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2024-28075 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-28075), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.