CVE-2021-31217
SolarWinds DameWare Mini Remote Control vulnerability analysis and mitigation

Overview

In SolarWinds DameWare Mini Remote Control Server 12.0.1.200, a vulnerability was discovered related to insecure file permissions that allowed file deletion with system-level access. The vulnerability was assigned CVE-2021-31217 and was disclosed in July 2021. The issue affected DameWare Mini Remote Control Server version 12.0.1.200 (SolarWinds Advisory).

Technical details

The vulnerability stems from insecure folder permissions of the Dameware Mini Remote Control Service installation. When a repair was initiated by the Windows Installer, the insecure permissions allowed privileged system-level file deletion. The vulnerability was rated as High severity (Rapid7).

Impact

The vulnerability could allow an attacker with local access to delete files with SYSTEM privileges, potentially impacting system availability and integrity (CVE Mitre).

Mitigation and workarounds

SolarWinds addressed this vulnerability in Dameware version 12.2. Due to improved security standards, Dameware 12.2 is not compatible with older agent versions. Users must remove existing agents and install version 12.2 either through the application or via the agent installer (SolarWinds Release Notes).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management