SolarWinds Orion Bug Allows Easy Remote-Code Execution and Takeover
#1
Information 
Quote:Three serious vulnerabilities have been found in SolarWinds products: Two in the Orion User Device Tracker and one in the Serv-U FTP for Windows product. The most severe of these could allow trivial remote code execution with high privileges.
 
The SolarWinds Orion platform is the network management tool at the heart of the recent espionage attack against several U.S. government agencies, tech companies and other high-profile targets. It allows users to manage devices, software and firmware versioning, applications and so on, and has full visibility into enterprise customer networks.
 
These fresh vulnerabilities have not been shown to be used in the spy attack, but admins should nonetheless apply patches as soon as possible, according to Martin Rakhmanov, security research manager for SpiderLabs at Trustwave.

Trustwave is not providing specific proof-of-concept (PoC) code until Feb. 9, in order to give SolarWinds users a longer time to patch, he noted in a Wednesday blog posting.

Read more: https://threatpost.com/solarwinds-orion-...on/163618/
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Hasleo Backup Suite V5.8.2.1
Hasleo Backup Suit...harlan4096 — 10:55
Notepad++ release 8.9.6
Notepad++ release ...harlan4096 — 10:53
Opera 131.0.5877.74
Hello! Opera 13...harlan4096 — 10:52
Vivaldi 8.0 Build 4033.26
Vivaldi 8.0 Build ...harlan4096 — 10:51
How an image could compromise your Mac: ...
A critical vulnera...harlan4096 — 10:50

[-]
Birthdays
Today's Birthdays
No birthdays today.
Upcoming Birthdays
avatar (39)axuben
avatar (40)ihijudu
avatar (50)Mirzojap
avatar (36)idilysaju
avatar (40)odukoromu
avatar (46)Joanna4589

[-]
Online Staff
There are no staff members currently online.

>