Remote Code Execution Vulnerability in SolarWinds Server and Application Monitor
CVE-2015-1501

Currently unrated

Key Information:

Vendor
Solarwinds
Vendor
CVE Published:
16 February 2015

Summary

The factory.loadExtensionFactory function in the TSUnicodeGraphEditorControl component of SolarWinds Server and Application Monitor permits remote attackers to execute arbitrary code. This is achieved by manipulating a UNC path that points to a specially crafted binary, leading to significant security risks for affected systems.

References

EPSS Score

20% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.