Lucene search

K
zdiPiotr Bazydlo (@chudypb) of Trend Micro Zero Day InitiativeZDI-22-1662
HistoryNov 23, 2022 - 12:00 a.m.

SolarWinds Network Performance Monitor WebUserSettingsCrudHandler Improper Input Validation Privilege Escalation Vulnerability

2022-11-2300:00:00
Piotr Bazydlo (@chudypb) of Trend Micro Zero Day Initiative
www.zerodayinitiative.com
11
remote attackers
privilege escalation
solarwinds npm
improper input validation

0.002 Low

EPSS

Percentile

55.6%

This vulnerability allows remote attackers to escalate privileges on affected installations of SolarWinds Network Performance Monitor. Authentication is required to exploit this vulnerability. The specific flaw exists within the CheckWhetherNonAdminAttemptsToModifyBlacklistedRecords function. The issue results from the lack of proper validation of the user-supplied SettingName parameter. An attacker can leverage this vulnerability to escalate privileges to resources normally protected from the user.

0.002 Low

EPSS

Percentile

55.6%

Related for ZDI-22-1662