
Cloud Vulnerability DB
A community-led vulnerabilities database
The CVE-2021-25274 vulnerability affects the SolarWinds Orion Platform versions before 2020.2.4. The vulnerability exists in the Collector Service which uses Microsoft Message Queue (MSMQ) without properly setting permissions on its private queues. This allows remote unauthenticated clients to send messages to TCP port 1801 that the Collector Service processes. The vulnerability was discovered in February 2021 and enables remote code execution with high privileges through insecure deserialization of messages (Trustwave Blog, NIST NVD).
The vulnerability stems from two key issues: First, the MSMQ queues are configured as unauthenticated, allowing any remote user to send messages to TCP port 1801. Second, when processing these messages, the service performs unsafe deserialization, leading to remote code execution. Since the message processing code runs as a Windows service configured with LocalSystem account privileges, successful exploitation provides complete control of the underlying operating system. The vulnerability has a CVSS v3.1 Base Score of 9.8 CRITICAL (Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) (NIST NVD).
Successful exploitation of this vulnerability allows attackers to execute arbitrary code with LocalSystem privileges, effectively gaining complete control over the affected Windows server. This level of access enables attackers to steal sensitive information, add new admin-level users, or take any other actions with system-level privileges (Trustwave Blog).
The vulnerability can be exploited remotely by unauthenticated users, making it highly exploitable. However, according to Trustwave's research, there was no evidence that this vulnerability was exploited during the SolarWinds attacks or in any 'in the wild' attacks (ZDNet).
SolarWinds has released patches to address this vulnerability in Orion Platform version 2020.2.4. After the patch is applied, there is a digital signature validation step performed on incoming messages, ensuring that messages without a signature or not signed with a per-installation certificate are not processed. Organizations are strongly advised to upgrade to the patched version as soon as possible (Trustwave Blog).
The discovery of this vulnerability came in the wake of the major SolarWinds supply chain attack, leading to heightened scrutiny of SolarWinds products. SolarWinds acknowledged that while vulnerabilities are common in all software products, they understand the increased attention and are committed to working with customers and organizations to identify and remediate any vulnerabilities across their product portfolio in a responsible way (ZDNet).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."