Lucene search

K
zdiPiotr Bazydlo (@chudypb) of Trend Micro Zero Day InitiativeZDI-22-1663
HistoryNov 23, 2022 - 12:00 a.m.

SolarWinds Network Performance Monitor GetPdf Command Injection Remote Code Execution Vulnerability

2022-11-2300:00:00
Piotr Bazydlo (@chudypb) of Trend Micro Zero Day Initiative
www.zerodayinitiative.com
11
remote code execution
solarwinds network performance monitor
authentication
getpdf function
system call

0.002 Low

EPSS

Percentile

62.0%

This vulnerability allows remote attackers to execute code on affected installations of SolarWinds Network Performance Monitor. Authentication is required to exploit this vulnerability. The specific flaw exists within the GetPdf function. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of SYSTEM.

0.002 Low

EPSS

Percentile

62.0%

Related for ZDI-22-1663