LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2024-28986: SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability

RBRecent Breaches Vulnerability Intelligence·Aug 15, 2024
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Sep 5, 2024
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2024-28986 to its Known Exploited Vulnerabilities catalog on Aug 15, 2024, with a federal patch deadline of Sep 5, 2024 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

SolarWinds Web Help Desk contains a deserialization of untrusted data vulnerability that could allow for remote code execution.

CVE-2024-28986 is a deserialization of untrusted data vulnerability in SolarWinds Web Help Desk. According to CISA, it could allow remote code execution. This matters because Web Help Desk often sits in IT support environments with access to tickets, assets, and internal systems; successful abuse can give an attacker a foothold for further activity. Confirm all version, configuration, and fix details against the vendor advisory.

How it works

The flaw is classified as CWE-502: deserialization of untrusted data. In this class of weakness, an application accepts serialized objects or data from a source it does not fully control and reconstructs them into live objects without adequate validation. When that process is unsafe, an attacker who can supply crafted input may influence what code runs during or after deserialization.

For SolarWinds Web Help Desk, public detail describes the outcome as possible remote code execution. Exact request paths, object types, or exploit mechanics are not provided here; treat any such claims as unverified until you review the vendor advisory and your own testing. In general, deserialization issues are abused by sending specially formed data that the application processes in a privileged context, potentially leading to arbitrary code execution under the service account.

Am I affected? How to find it in your systems

SolarWinds Web Help Desk is typically deployed as an on-premises or self-hosted IT service management / help-desk application used by internal support teams. It may run on Windows servers and is often reachable from the corporate network or, in some cases, from the internet if exposed for remote support.

How to remediate

Patch first. Apply the mitigations and updates provided by SolarWinds for this vulnerability, following the vendor instructions exactly. CISA’s required action is to apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

If you can't patch immediately

Until the vendor update can be applied, reduce risk with compensating controls:

If your data may have been exposed

Actively exploited vulnerabilities of this type can lead to unauthorized access and data exposure. Known ransomware use is not documented for this CVE. If you suspect compromise, follow your incident-response process: isolate affected systems, preserve evidence, and assess what data the help-desk application could have accessed. You can also run a free exposure scan of your email addresses against known breach data to check whether credentials or personal information associated with your organization already appear in public breach collections.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedSolarWinds · Web Help Desk
WeaknessCWE-502
Added to CISA KEVAug 15, 2024
Federal patch deadlineSep 5, 2024
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities