CVE-2021-25274
SolarWinds Platform vulnerability analysis and mitigation

Overview

The CVE-2021-25274 vulnerability affects the SolarWinds Orion Platform versions before 2020.2.4. The vulnerability exists in the Collector Service which uses Microsoft Message Queue (MSMQ) without properly setting permissions on its private queues. This allows remote unauthenticated clients to send messages to TCP port 1801 that the Collector Service processes. The vulnerability was discovered in February 2021 and enables remote code execution with high privileges through insecure deserialization of messages (Trustwave Blog, NIST NVD).

Technical details

The vulnerability stems from two key issues: First, the MSMQ queues are configured as unauthenticated, allowing any remote user to send messages to TCP port 1801. Second, when processing these messages, the service performs unsafe deserialization, leading to remote code execution. Since the message processing code runs as a Windows service configured with LocalSystem account privileges, successful exploitation provides complete control of the underlying operating system. The vulnerability has a CVSS v3.1 Base Score of 9.8 CRITICAL (Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) (NIST NVD).

Impact

Successful exploitation of this vulnerability allows attackers to execute arbitrary code with LocalSystem privileges, effectively gaining complete control over the affected Windows server. This level of access enables attackers to steal sensitive information, add new admin-level users, or take any other actions with system-level privileges (Trustwave Blog).

Exploitability

The vulnerability can be exploited remotely by unauthenticated users, making it highly exploitable. However, according to Trustwave's research, there was no evidence that this vulnerability was exploited during the SolarWinds attacks or in any 'in the wild' attacks (ZDNet).

Mitigation and workarounds

SolarWinds has released patches to address this vulnerability in Orion Platform version 2020.2.4. After the patch is applied, there is a digital signature validation step performed on incoming messages, ensuring that messages without a signature or not signed with a per-installation certificate are not processed. Organizations are strongly advised to upgrade to the patched version as soon as possible (Trustwave Blog).

Community reactions

The discovery of this vulnerability came in the wake of the major SolarWinds supply chain attack, leading to heightened scrutiny of SolarWinds products. SolarWinds acknowledged that while vulnerabilities are common in all software products, they understand the increased attention and are committed to working with customers and organizations to identify and remediate any vulnerabilities across their product portfolio in a responsible way (ZDNet).

Additional resources


SourceThis report was generated using AI

Related SolarWinds Platform vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2024-52606CRITICAL9.8
  • SolarWinds Platform logoSolarWinds Platform
  • cpe:2.3:a:solarwinds:solarwinds_platform
NoYesFeb 11, 2025
CVE-2024-45715MEDIUM5.2
  • SolarWinds Platform logoSolarWinds Platform
  • cpe:2.3:a:solarwinds:solarwinds_platform
NoYesOct 16, 2024
CVE-2024-52612MEDIUM4.8
  • SolarWinds Platform logoSolarWinds Platform
  • cpe:2.3:a:solarwinds:solarwinds_platform
NoYesFeb 11, 2025
CVE-2024-45717MEDIUM4.8
  • SolarWinds Platform logoSolarWinds Platform
  • cpe:2.3:a:solarwinds:solarwinds_platform
NoYesDec 04, 2024
CVE-2024-52611LOW3.5
  • SolarWinds Platform logoSolarWinds Platform
  • cpe:2.3:a:solarwinds:solarwinds_platform
NoYesFeb 11, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management