HomeVulnerabilitySolarWinds releases third patch to repair Internet Assist Desk RCE bug

SolarWinds releases third patch to repair Internet Assist Desk RCE bug

SolarWinds has launched a hotfix for a important a important vulnerability in Internet Assist Desk that enables distant code execution (RCE) with out authentication.

Tracked as CVE-2025-26399, the security concern is the corporate’s third try to handle an older flaw recognized as CVE-2024-28986 that impacted Internet Assist Desk (WHD) 12.8.3 and all earlier variations.

SolarWinds WHD is a assist desk and ticketing suite utilized by medium-to-large organizations for IT help request monitoring, workflow automation, asset administration, and compliance assurance.

CVE-2025-26399 impacts the newest WHD model 12.8.7 and is brought on by unsafe deserialization dealing with within the AjaxProxy part. Profitable exploitation permits an unauthenticated attacker to run instructions on the host machine.

In a security bulletin, the seller says that “this vulnerability is a patch bypass of CVE-2024-28988, which in flip is a patch bypass of CVE-2024-28986.”

Final August, the U.S. Cybersecurity and Infrastructure Safety Company (CISA) marked the unique SolarWinds flaw as being leveraged in assaults and added it to the Recognized Exploited Vulnerabilities (KEV) catalog.

See also  Vital FortiSIEM CVEs are duplicates, issued in error

The brand new security drawback was reported to SolarWinds via the Development Micro Zero Day Initiative (ZDI). On the time of writing there are not any public studies about risk actors exploiting it.

Hotfix out there

SolarWinds has launched a hotfix that addresses CVE-2025-26399, which requires putting in Internet Assist Desk model 12.8.7. To use the security replace, customers are suggested to observe these steps:

  1. Cease Internet Assist Desk
  2. Navigate to: <WebHelpDesk>/bin/webapps/helpdesk/WEB-INF/lib/ (substitute <WebHelpDesk> relying on OS)
  3. Again up after which delete: c3p0.jar
  4. Again up (to a separate listing): whd-core.jar, whd-web.jar, whd-persistence.jar
  5. Copy the hotfix-supplied JARs into the identical /lib listing, overwriting the originals: whd-core.jar, whd-web.jar, whd-persistence.jar, plus add HikariCP.jar
  6. Restart Internet Assist Desk

The hotfix is completely out there via the SolarWinds Buyer Portal. Extra info on the best way to improve WHD is out there right here.

- Advertisment -spot_img
RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

- Advertisment -

Most Popular