Sunday, June 1, 2025
No Result
View All Result
  • Home
  • Guest Post
  • Submit Review Article
  • Contact
Somali Update
  • Headlines
    • Politics
  • Auto
    • Bike
    • Car
  • Business
    • Finance
    • Funding
    • Internet Marketing
    • Entrepreneurship
    • Startups
    • Insurance
    • Real Estate
  • Crypto
    • Bitcoin
    • Ethereum
    • Altcoins
    • Crypto Airdrop
    • ICO News
  • Entertainment
    • Poll
    • Quiz
  • Lifestyle
    • Health
    • Fashion
    • Food
    • Romance
    • Travel
  • Sports
    • Baseball
    • Basketball
    • Cricket
    • Football
    • Hockey
    • NFL
    • Tennis
    • WWE
  • Tech
    • Gadgets
    • Hardware
    • Software
    • Android
    • iOS
    • Social Media
  • Casino
    • Betting
  • Headlines
    • Politics
  • Auto
    • Bike
    • Car
  • Business
    • Finance
    • Funding
    • Internet Marketing
    • Entrepreneurship
    • Startups
    • Insurance
    • Real Estate
  • Crypto
    • Bitcoin
    • Ethereum
    • Altcoins
    • Crypto Airdrop
    • ICO News
  • Entertainment
    • Poll
    • Quiz
  • Lifestyle
    • Health
    • Fashion
    • Food
    • Romance
    • Travel
  • Sports
    • Baseball
    • Basketball
    • Cricket
    • Football
    • Hockey
    • NFL
    • Tennis
    • WWE
  • Tech
    • Gadgets
    • Hardware
    • Software
    • Android
    • iOS
    • Social Media
  • Casino
    • Betting
No Result
View All Result
Somali Update
No Result
View All Result

SolarWinds fixes critical flaws in access management software

by Susan James
1 year ago
in Technology
Reading Time: 2 mins read
0
Home Technology
Share on FacebookShare on TwitterShare on WhatsAppShare on Telegram

SolarWinds, the company that was hit by a massive cyberattack in 2020, has released security updates for its Access Rights Manager (ARM) software, which is used to manage and audit access to Microsoft resources. The updates address five remote code execution (RCE) vulnerabilities, three of which are rated critical.

RCE vulnerabilities allow attackers to execute code remotely

The critical RCE vulnerabilities, identified as CVE-2023-40057, CVE-2024-23476, and CVE-2024-23479, were discovered and reported by Trend Micro’s Zero Day Initiative (ZDI). They affect how the ARM software handles deserialization of untrusted data and file paths. If exploited, these vulnerabilities could allow an authenticated or unauthenticated attacker to execute code in the context of the SolarWinds service or the system user.

According to SolarWinds’ advisory, CVE-2023-40057 is a bug in the createGlobalServerChannelInternal method, which can result in deserialization of untrusted data. CVE-2024-23476 and CVE-2024-23479 are both directory traversal bugs, which occur in the OpenFile and OpenClientUpdateFile methods, respectively. These bugs can allow an attacker to access files outside of the intended directory.

SolarWinds also patches two high-rated bugs in Orion Platform

In addition to the five RCE vulnerabilities in ARM, SolarWinds also disclosed two high-rated bugs in its Orion Platform, which was the main target of the 2020 cyberattack. These bugs, CVE-2023-50395 and CVE-2023-35188, are both SQL injection vulnerabilities that affect an update statement and a create statement, respectively. SolarWinds said that these bugs can only be exploited by an authenticated user, and have not been seen in the wild.

SolarWinds fixes critical flaws in access management software
SolarWinds fixes critical flaws in access management software

The Orion Platform is a suite of network management tools that is used by thousands of customers, including government agencies and Fortune 500 companies. In 2020, hackers compromised the Orion Platform by inserting malicious code into its software updates, which allowed them to access the networks of SolarWinds’ customers and steal sensitive data. The attack was attributed to a Russian state-sponsored group known as APT29 or Cozy Bear.

SolarWinds urges customers to apply the security updates as soon as possible

SolarWinds has patched the vulnerabilities in the latest versions of its software: ARM 2023.2.3 and Orion Platform 2023.2.6. The company has advised its customers to apply the security updates as soon as possible to protect their systems from potential attacks. SolarWinds has also provided mitigation steps for customers who cannot update their software immediately.

SolarWinds has been working to improve its security posture and regain the trust of its customers after the 2020 cyberattack. The company has hired a new chief information security officer, hired external security experts, implemented new security tools and processes, and launched a secure by design program. SolarWinds has also cooperated with law enforcement and government agencies to investigate the attack and prevent future incidents.

Susan James

Susan James

Susan James is a talented author and a skilled content writer. As a content writer, Susan has honed her skills in researching and understanding various topics, allowing her to produce well-rounded and engaging pieces across a wide range of subjects.

Related Posts

minimalist portable writing setup raspberry pi screen keyboard

Building Focus: How a DIY Writer’s Deck Helps Beat Digital Distractions

1 day ago
smiling person laptop outdoor stock market investing

Why These 4 Dow Titans Could Anchor Your Portfolio for the Next Decade

1 day ago
NES Zapper light sensor mod project

How a Classic NES Zapper Became a Surprising Wireless Phone

6 days ago
raspberry pi arcade buttons remote work

How This DIY Raspberry Pi Gadget Makes Remote Work Calls Way Easier

1 week ago
Samsung 9100 Pro PCIe 5.0 SSD close-up with heatsink

Samsung’s 9100 Pro SSD Hits a Sweet Spot With Price Drop and Blazing Speeds

1 week ago
soundhound ai speech recognition app interface

Why Some Beaten-Down Tech Stocks Might Be Setting Up for a Parabolic Rebound

1 week ago

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

SEARCH

No Result
View All Result

TRENDING

  • Trending
  • Comments
  • Latest
Raja Rani Coupon Result

Raja Rani Result Today: Raja Rani Result 28th August Live Updates

August 28, 2024
SkymoviesHD

SkymoviesHD Proxy to Unblock Site – SkymoviesHD Movies Download

March 6, 2024
Control Bionics Secures Major US Reimbursement for NeuroNode Device

Control Bionics Secures Major US Reimbursement for NeuroNode Device

August 19, 2024
Moviesda

Moviesda Proxy to Unblock Links – Moviesda Movie Download

March 6, 2024
near lossless electrical transmission discovery by mit scientists

Near-Lossless Electrical Transmission: A Breakthrough by MIT Scientists

September 12, 2024
Bigg Boss 7 Tamil Contestants Salary

Bigg Boss 7 Tamil Contestants Salary Per Day Revealed

January 9, 2024
Vegamovies

Vegamovies Proxy to Unblock Links – Vegamovies Movies Download

March 6, 2024
iBOMMA

iBOMMA Proxy to Unblock, Movies – IBOMMA Movie Download

March 6, 2024
Kolkata FF Fatafat Result

Kolkata FF Fatafat Result 24th January 2024 Live Updates

January 24, 2024
Tamilblasters

TamilBlasters Proxy – Unblock Links, Tamilblasters Movies Download

March 6, 2024

Business Ideas with Low Investment and High Profit

1
Bhutan Teer Result 2021

Bhutan Teer Result Today Live: Bhutan Teer Result 3rd January Update

1

Reasons to Join the PKT Cash Crypto Network

1
Kolkata FF Fatafat Result

Kolkata FF Fatafat Result 24th January 2024 Live Updates

1
Coinbase

Coinbase Crypto Exchange hires Jeff Horowitz as their CCO

0
Kucoin

KuCoin Scam? Office Location issue clarified

0
Nokia 5G mobile

Nokia 5G Mobile to be launched with T-Mobile soon

0
CasinoBuzz

Casino.Buzz: One of the most Informative Online Casino Review Website

0
Facebook Ban alex jones

Facebook Suspends Alex Jones for Hate Speech

0
Good Rummy Party

What Makes a Good Rummy Party?

0
minimalist portable writing setup raspberry pi screen keyboard

Building Focus: How a DIY Writer’s Deck Helps Beat Digital Distractions

May 31, 2025
smiling person laptop outdoor stock market investing

Why These 4 Dow Titans Could Anchor Your Portfolio for the Next Decade

May 31, 2025
Star Wars Battlefront II gameplay multiplayer steam resurgence

Star Wars Battlefront II Makes a Stunning Comeback Nearly Eight Years After Launch

May 30, 2025
dividend stocks quarterly increase investors income growth

These Dividend Stocks Are Raising Payouts Every Quarter—Here’s Why Investors Are Taking Notice

May 30, 2025
Kevin Costner filming Horizon American Saga

Stunt Performer Sues Kevin Costner Over Alleged Unscripted Assault on “Horizon” Set

May 29, 2025
Nvidia CEO Jensen Huang GTC 2025 keynote

Nvidia Shatters Expectations with Record Revenue Amid AI Boom

May 29, 2025
India power infrastructure transmission lines growth

GE Vernova T&D India Ltd Surges to Triple Net Profit on Strong Power Infrastructure Demand

May 27, 2025
World Pride 2025 Washington DC performers

Grimes Cancels World Pride Performance, Citing Family Issues

May 27, 2025
netflix logo building top streaming media

Netflix Aims for a $1 Trillion Valuation by 2030—Here’s What Could Get It There

May 27, 2025
NES Zapper light sensor mod project

How a Classic NES Zapper Became a Surprising Wireless Phone

May 26, 2025

ABOUT US

From global politics to cultural trends, we bring you comprehensive coverage and diverse perspectives. Stay connected with the international community and explore stories from around the globe. Engage with our thought-provoking articles and stay informed about the world’s most pressing issues.

Contact us at ceo.somaliupdate@gmail.com

ADVERTISE WITH US

We accept following advertisement methods in our website.

  • Guest Post
  • Sponsored Post
  • Banner Ad
  • Homepage Ad
  • Sidebar Ad
  • Niche Edit
  • Link Ad
  • Review Article

POPULAR CATEGORIES

List of Popular categories in our websites which are loved more frequently by our beloved readers.

  • AUTO
  • BUSINESS
  • CRYPTO
  • GAMBLING
  • SPORTS
  • TECH
  • HEALTH

THIS WEEK POLLS

Sorry, there are no polls available at the moment.
  • Polls Archive
  • Home
  • Guest Post
  • Submit Review Article
  • Contact

© 2023 SOMALIUPDATE - Developed by VISION

No Result
View All Result
  • Headlines
    • Politics
  • Auto
    • Bike
    • Car
  • Business
    • Finance
    • Funding
    • Internet Marketing
    • Entrepreneurship
    • Startups
    • Insurance
    • Real Estate
  • Crypto
    • Bitcoin
    • Ethereum
    • Altcoins
    • Crypto Airdrop
    • ICO News
  • Entertainment
    • Poll
    • Quiz
  • Lifestyle
    • Health
    • Fashion
    • Food
    • Romance
    • Travel
  • Sports
    • Baseball
    • Basketball
    • Cricket
    • Football
    • Hockey
    • NFL
    • Tennis
    • WWE
  • Tech
    • Gadgets
    • Hardware
    • Software
    • Android
    • iOS
    • Social Media
  • Casino
    • Betting

© 2023 SOMALIUPDATE - Developed by VISION