Saturday, May 24, 2025
No Result
View All Result
  • Home
  • Guest Post
  • Submit Review Article
  • Contact
Somali Update
  • Headlines
    • Politics
  • Auto
    • Bike
    • Car
  • Business
    • Finance
    • Funding
    • Internet Marketing
    • Entrepreneurship
    • Startups
    • Insurance
    • Real Estate
  • Crypto
    • Bitcoin
    • Ethereum
    • Altcoins
    • Crypto Airdrop
    • ICO News
  • Entertainment
    • Poll
    • Quiz
  • Lifestyle
    • Health
    • Fashion
    • Food
    • Romance
    • Travel
  • Sports
    • Baseball
    • Basketball
    • Cricket
    • Football
    • Hockey
    • NFL
    • Tennis
    • WWE
  • Tech
    • Gadgets
    • Hardware
    • Software
    • Android
    • iOS
    • Social Media
  • Casino
    • Betting
  • Headlines
    • Politics
  • Auto
    • Bike
    • Car
  • Business
    • Finance
    • Funding
    • Internet Marketing
    • Entrepreneurship
    • Startups
    • Insurance
    • Real Estate
  • Crypto
    • Bitcoin
    • Ethereum
    • Altcoins
    • Crypto Airdrop
    • ICO News
  • Entertainment
    • Poll
    • Quiz
  • Lifestyle
    • Health
    • Fashion
    • Food
    • Romance
    • Travel
  • Sports
    • Baseball
    • Basketball
    • Cricket
    • Football
    • Hockey
    • NFL
    • Tennis
    • WWE
  • Tech
    • Gadgets
    • Hardware
    • Software
    • Android
    • iOS
    • Social Media
  • Casino
    • Betting
No Result
View All Result
Somali Update
No Result
View All Result

SolarWinds fixes critical flaws in access management software

by Susan James
1 year ago
in Technology
Reading Time: 2 mins read
0
Home Technology
Share on FacebookShare on TwitterShare on WhatsAppShare on Telegram

SolarWinds, the company that was hit by a massive cyberattack in 2020, has released security updates for its Access Rights Manager (ARM) software, which is used to manage and audit access to Microsoft resources. The updates address five remote code execution (RCE) vulnerabilities, three of which are rated critical.

RCE vulnerabilities allow attackers to execute code remotely

The critical RCE vulnerabilities, identified as CVE-2023-40057, CVE-2024-23476, and CVE-2024-23479, were discovered and reported by Trend Micro’s Zero Day Initiative (ZDI). They affect how the ARM software handles deserialization of untrusted data and file paths. If exploited, these vulnerabilities could allow an authenticated or unauthenticated attacker to execute code in the context of the SolarWinds service or the system user.

According to SolarWinds’ advisory, CVE-2023-40057 is a bug in the createGlobalServerChannelInternal method, which can result in deserialization of untrusted data. CVE-2024-23476 and CVE-2024-23479 are both directory traversal bugs, which occur in the OpenFile and OpenClientUpdateFile methods, respectively. These bugs can allow an attacker to access files outside of the intended directory.

SolarWinds also patches two high-rated bugs in Orion Platform

In addition to the five RCE vulnerabilities in ARM, SolarWinds also disclosed two high-rated bugs in its Orion Platform, which was the main target of the 2020 cyberattack. These bugs, CVE-2023-50395 and CVE-2023-35188, are both SQL injection vulnerabilities that affect an update statement and a create statement, respectively. SolarWinds said that these bugs can only be exploited by an authenticated user, and have not been seen in the wild.

SolarWinds fixes critical flaws in access management software
SolarWinds fixes critical flaws in access management software

The Orion Platform is a suite of network management tools that is used by thousands of customers, including government agencies and Fortune 500 companies. In 2020, hackers compromised the Orion Platform by inserting malicious code into its software updates, which allowed them to access the networks of SolarWinds’ customers and steal sensitive data. The attack was attributed to a Russian state-sponsored group known as APT29 or Cozy Bear.

SolarWinds urges customers to apply the security updates as soon as possible

SolarWinds has patched the vulnerabilities in the latest versions of its software: ARM 2023.2.3 and Orion Platform 2023.2.6. The company has advised its customers to apply the security updates as soon as possible to protect their systems from potential attacks. SolarWinds has also provided mitigation steps for customers who cannot update their software immediately.

SolarWinds has been working to improve its security posture and regain the trust of its customers after the 2020 cyberattack. The company has hired a new chief information security officer, hired external security experts, implemented new security tools and processes, and launched a secure by design program. SolarWinds has also cooperated with law enforcement and government agencies to investigate the attack and prevent future incidents.

Susan James

Susan James

Susan James is a talented author and a skilled content writer. As a content writer, Susan has honed her skills in researching and understanding various topics, allowing her to produce well-rounded and engaging pieces across a wide range of subjects.

Related Posts

raspberry pi arcade buttons remote work

How This DIY Raspberry Pi Gadget Makes Remote Work Calls Way Easier

1 day ago
Samsung 9100 Pro PCIe 5.0 SSD close-up with heatsink

Samsung’s 9100 Pro SSD Hits a Sweet Spot With Price Drop and Blazing Speeds

2 days ago
soundhound ai speech recognition app interface

Why Some Beaten-Down Tech Stocks Might Be Setting Up for a Parabolic Rebound

2 days ago
microsoft teams emoji reactions update 2025

Microsoft Teams to Finally Let Users React with Multiple Emojis After Years of Waiting

4 days ago
AI data center infrastructure

Three Stocks Set to Ride the AI Boom: Infrastructure, Energy, and Connectivity

4 days ago
acer freesense ring ai transbuds computex 2025 showcase

Acer Bets on Smart Wearables With Health-Focused Ring and Real-Time AI Earbuds

5 days ago

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

SEARCH

No Result
View All Result

TRENDING

  • Trending
  • Comments
  • Latest
Raja Rani Coupon Result

Raja Rani Result Today: Raja Rani Result 28th August Live Updates

August 28, 2024
SkymoviesHD

SkymoviesHD Proxy to Unblock Site – SkymoviesHD Movies Download

March 6, 2024
Control Bionics Secures Major US Reimbursement for NeuroNode Device

Control Bionics Secures Major US Reimbursement for NeuroNode Device

August 19, 2024
Moviesda

Moviesda Proxy to Unblock Links – Moviesda Movie Download

March 6, 2024
near lossless electrical transmission discovery by mit scientists

Near-Lossless Electrical Transmission: A Breakthrough by MIT Scientists

September 12, 2024
Bigg Boss 7 Tamil Contestants Salary

Bigg Boss 7 Tamil Contestants Salary Per Day Revealed

January 9, 2024
Vegamovies

Vegamovies Proxy to Unblock Links – Vegamovies Movies Download

March 6, 2024
iBOMMA

iBOMMA Proxy to Unblock, Movies – IBOMMA Movie Download

March 6, 2024
Kolkata FF Fatafat Result

Kolkata FF Fatafat Result 24th January 2024 Live Updates

January 24, 2024
Tamilblasters

TamilBlasters Proxy – Unblock Links, Tamilblasters Movies Download

March 6, 2024

Business Ideas with Low Investment and High Profit

1
Bhutan Teer Result 2021

Bhutan Teer Result Today Live: Bhutan Teer Result 3rd January Update

1

Reasons to Join the PKT Cash Crypto Network

1
Kolkata FF Fatafat Result

Kolkata FF Fatafat Result 24th January 2024 Live Updates

1
Coinbase

Coinbase Crypto Exchange hires Jeff Horowitz as their CCO

0
Kucoin

KuCoin Scam? Office Location issue clarified

0
Nokia 5G mobile

Nokia 5G Mobile to be launched with T-Mobile soon

0
CasinoBuzz

Casino.Buzz: One of the most Informative Online Casino Review Website

0
Facebook Ban alex jones

Facebook Suspends Alex Jones for Hate Speech

0
Good Rummy Party

What Makes a Good Rummy Party?

0
Indiana Pacers vs New York Knicks playoff game 2024

Pacers Stun Knicks Again, Take Commanding 2-0 Lead in Eastern Conference Series

May 24, 2025
Warren Buffett Berkshire Hathaway shareholder meeting

Trump’s Tariffs Shake Markets: Why Berkshire Hathaway and Nucor Are Standing Out

May 24, 2025
raspberry pi arcade buttons remote work

How This DIY Raspberry Pi Gadget Makes Remote Work Calls Way Easier

May 23, 2025
AMD and PTC semiconductor industry

Two Slumping Stocks With Big Upside: AMD and PTC Worth a Second Look

May 23, 2025
Samsung 9100 Pro PCIe 5.0 SSD close-up with heatsink

Samsung’s 9100 Pro SSD Hits a Sweet Spot With Price Drop and Blazing Speeds

May 22, 2025
soundhound ai speech recognition app interface

Why Some Beaten-Down Tech Stocks Might Be Setting Up for a Parabolic Rebound

May 22, 2025
Zoey Stark WWE knee injury springboard dropkick Raw

WWE Superstar Zoey Stark Suffers Knee Injury During Monday Night Raw Match

May 20, 2025
microsoft teams emoji reactions update 2025

Microsoft Teams to Finally Let Users React with Multiple Emojis After Years of Waiting

May 20, 2025
AI data center infrastructure

Three Stocks Set to Ride the AI Boom: Infrastructure, Energy, and Connectivity

May 20, 2025
acer freesense ring ai transbuds computex 2025 showcase

Acer Bets on Smart Wearables With Health-Focused Ring and Real-Time AI Earbuds

May 19, 2025

ABOUT US

From global politics to cultural trends, we bring you comprehensive coverage and diverse perspectives. Stay connected with the international community and explore stories from around the globe. Engage with our thought-provoking articles and stay informed about the world’s most pressing issues.

Contact us at ceo.somaliupdate@gmail.com

ADVERTISE WITH US

We accept following advertisement methods in our website.

  • Guest Post
  • Sponsored Post
  • Banner Ad
  • Homepage Ad
  • Sidebar Ad
  • Niche Edit
  • Link Ad
  • Review Article

POPULAR CATEGORIES

List of Popular categories in our websites which are loved more frequently by our beloved readers.

  • AUTO
  • BUSINESS
  • CRYPTO
  • GAMBLING
  • SPORTS
  • TECH
  • HEALTH

THIS WEEK POLLS

Sorry, there are no polls available at the moment.
  • Polls Archive
  • Home
  • Guest Post
  • Submit Review Article
  • Contact

© 2023 SOMALIUPDATE - Developed by VISION

No Result
View All Result
  • Headlines
    • Politics
  • Auto
    • Bike
    • Car
  • Business
    • Finance
    • Funding
    • Internet Marketing
    • Entrepreneurship
    • Startups
    • Insurance
    • Real Estate
  • Crypto
    • Bitcoin
    • Ethereum
    • Altcoins
    • Crypto Airdrop
    • ICO News
  • Entertainment
    • Poll
    • Quiz
  • Lifestyle
    • Health
    • Fashion
    • Food
    • Romance
    • Travel
  • Sports
    • Baseball
    • Basketball
    • Cricket
    • Football
    • Hockey
    • NFL
    • Tennis
    • WWE
  • Tech
    • Gadgets
    • Hardware
    • Software
    • Android
    • iOS
    • Social Media
  • Casino
    • Betting

© 2023 SOMALIUPDATE - Developed by VISION