EXPOSURES › CVE-2024-28986
CVE-2024-28986
HIGH ⌖ ON CISA KEV · EXPLOITEDSolarWinds Web Help Desk allows remote code execution via deserialization of untrusted data, a high-severity vulnerability actively exploited in the wild.
This vulnerability enables attackers to execute arbitrary code on SolarWinds-managed systems, posing a severe risk to defense contractors relying on SolarWinds tools for network management and help desk operations. DIB organizations must immediately patch affected systems and audit all SolarWinds deployments to prevent unauthorized access to sensitive data.
Shame score — A high-severity RCE vulnerability in a widely used product that is actively exploited in the wild represents a significant security failure.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
SolarWinds Web Help Desk contains a deserialization of untrusted data vulnerability that could allow for remote code execution.