Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2024-23465

CVE-2024-23465: SolarWinds ARM Authentication Bypass Flaw

CVE-2024-23465 is an authentication bypass flaw in SolarWinds Access Rights Manager that lets unauthenticated attackers gain domain admin privileges in Active Directory. This article covers technical details, affected versions, security impact, and mitigation guidance.

Published:

CVE-2024-23465 Overview

CVE-2024-23465 is an authentication bypass vulnerability in SolarWinds Access Rights Manager (ARM). The flaw allows an unauthenticated attacker on an adjacent network to bypass authentication controls and obtain domain administrator access within the Active Directory environment managed by ARM. The vulnerability is classified under [CWE-287] Improper Authentication. SolarWinds addressed the issue in the ARM 2024.3 release.

Critical Impact

An unauthenticated attacker with adjacent network access can escalate to domain administrator privileges, resulting in full compromise of the Active Directory environment and all resources it protects.

Affected Products

  • SolarWinds Access Rights Manager (versions prior to 2024.3)
  • Deployments integrating ARM with Active Directory
  • Environments where the ARM server is reachable from an adjacent network segment

Discovery Timeline

  • 2024-07-17 - CVE-2024-23465 published to the National Vulnerability Database
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2024-23465

Vulnerability Analysis

SolarWinds Access Rights Manager is an identity governance product used to audit, manage, and provision access across Active Directory, Exchange, SharePoint, and file servers. Because ARM operates with privileged service accounts and interacts directly with domain controllers, any authentication weakness in the product translates directly into Active Directory risk.

CVE-2024-23465 permits an unauthenticated user on an adjacent network to circumvent ARM's authentication layer. Once the bypass succeeds, the attacker inherits the privileges available through the ARM service context and can leverage them to obtain domain administrator rights. This grants control over user accounts, group memberships, Group Policy, and domain-joined systems.

The attack vector is Adjacent (AV:A), meaning the attacker must reside on the same logical network segment or broadcast domain as the ARM server. No user interaction and no prior privileges are required.

Root Cause

The defect resides in the authentication handling logic of the ARM product. The affected code path fails to correctly validate the identity of the requesting client before granting access to privileged functionality. SolarWinds has not published low-level implementation details, but the CWE-287 classification confirms improper authentication rather than authorization or session-management errors.

Attack Vector

An attacker positioned on an adjacent network sends crafted requests to the ARM service endpoint. Because authentication is bypassed, the ARM component processes these requests as if issued by a trusted principal. The attacker then invokes ARM operations that create, modify, or elevate accounts inside Active Directory, resulting in domain-admin-level access.

No verified public proof-of-concept exploit is available at this time. Refer to the SolarWinds ARM 2024.3 Release Notes for vendor-supplied details.

Detection Methods for CVE-2024-23465

Indicators of Compromise

  • Unexpected creation of privileged Active Directory accounts or additions to Domain Admins, Enterprise Admins, or Schema Admins groups originating from the ARM service account.
  • Anomalous ARM API or web-console requests from hosts that are not documented ARM administrators or integration systems.
  • ARM audit logs showing high-privilege operations without a corresponding authenticated administrator session.

Detection Strategies

  • Correlate ARM application logs with domain controller Security event logs (Event IDs 4720, 4728, 4732, 4756) to identify account changes initiated through ARM without a matching interactive logon.
  • Baseline normal ARM client sources and alert on connections from unexpected subnets, especially untrusted or user VLANs adjacent to the ARM server.
  • Monitor Kerberos and NTLM authentication activity for the ARM service account for spikes tied to privileged directory operations.

Monitoring Recommendations

  • Forward ARM, Windows Security, and directory-service logs to a centralized analytics platform with retention sufficient to reconstruct multi-step activity.
  • Alert on any use of the ARM service account outside its documented maintenance windows or automation schedule.
  • Track group membership changes for tier-0 Active Directory groups in near real time.

How to Mitigate CVE-2024-23465

Immediate Actions Required

  • Upgrade SolarWinds Access Rights Manager to version 2024.3 or later, which contains the vendor fix for CVE-2024-23465.
  • Restrict network reachability of the ARM server to a dedicated management VLAN using host and network firewalls.
  • Review Active Directory for unauthorized account creations, group changes, or privilege escalations dating back to before the patch was applied.
  • Rotate credentials for the ARM service account and any domain accounts that ARM manages with elevated rights.

Patch Information

SolarWinds released the fix in Access Rights Manager 2024.3. Deployment guidance and the full changelog are available in the SolarWinds ARM 2024.3 Release Notes. Apply the update to all ARM servers and any distributed collector components in the environment.

Workarounds

  • Isolate the ARM server on a management-only network segment and block adjacent-network access from user and server VLANs until the patch is applied.
  • Require VPN or jump-host access with multi-factor authentication for all ARM administrative sessions.
  • Temporarily reduce the privileges granted to the ARM service account to the minimum required, then restore them after patching if broader rights are needed for operations.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.