Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2024-23469

CVE-2024-23469: SolarWinds Access Rights Manager RCE Flaw

CVE-2024-23469 is a remote code execution vulnerability in SolarWinds Access Rights Manager that allows unauthenticated attackers to execute code with SYSTEM privileges. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2024-23469 Overview

CVE-2024-23469 is a remote code execution (RCE) vulnerability in SolarWinds Access Rights Manager (ARM). The flaw allows an unauthenticated attacker on an adjacent network to execute code with SYSTEM privileges on the affected host. SolarWinds tracked the issue under CWE-20: Improper Input Validation and remediated it in the ARM 2024.3 release. The Exploit Prediction Scoring System (EPSS) places this CVE in the 96.9th percentile, indicating elevated real-world exploitation likelihood compared to the broader CVE population.

Critical Impact

An unauthenticated adjacent-network attacker can gain SYSTEM-level code execution on ARM servers, giving full control over identity and access governance data across the enterprise.

Affected Products

  • SolarWinds Access Rights Manager (ARM) versions prior to 2024.3
  • Windows-based ARM server deployments
  • Environments where ARM is reachable on the local or adjacent network segment

Discovery Timeline

  • 2024-07-17 - CVE-2024-23469 published to the National Vulnerability Database (NVD)
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2024-23469

Vulnerability Analysis

SolarWinds Access Rights Manager centralizes permissions management across Active Directory, file servers, Exchange, and SharePoint. The product runs privileged Windows services on the ARM host to enumerate and modify access rights. CVE-2024-23469 exposes a code path in these privileged services that accepts network input without adequate validation.

Because the vulnerable interface listens on an adjacent-network attack surface and requires no authentication, any attacker with a foothold on the same broadcast domain or VLAN as the ARM server can reach it. Successful exploitation yields arbitrary code execution in the security context of the ARM service account, which runs as SYSTEM. From that position, an attacker can pivot into Active Directory, harvest credentials, and modify permissions across every system ARM manages.

Root Cause

The root cause is improper input validation [CWE-20] in an ARM service component that processes network requests. The service deserializes or interprets attacker-controlled data without enforcing the type, structure, or length constraints required to keep the parsing logic within safe bounds. SolarWinds has not publicly disclosed the specific component or wire protocol involved.

Attack Vector

The attack vector is Adjacent Network (AV:A), meaning the attacker must share a logical network segment with the target rather than reaching it across the public internet. No credentials and no user interaction are required. An attacker who has already breached a workstation on the internal network can chain that access with CVE-2024-23469 to escalate from user-level access on an endpoint to SYSTEM on the ARM server. Refer to the SolarWinds ARM 2024.3 Release Notes for the vendor's advisory.

Detection Methods for CVE-2024-23469

Indicators of Compromise

  • Unexpected child processes spawned by ARM service executables running as SYSTEM
  • New or modified scheduled tasks, services, or persistence artifacts on the ARM host
  • Outbound network connections from the ARM server to previously unseen internal or external hosts
  • Anomalous privileged Active Directory operations (group membership changes, ACL edits) originating from the ARM service account

Detection Strategies

  • Baseline the process tree of ARM services and alert on deviations such as cmd.exe, powershell.exe, or scripting hosts launched by ARM binaries
  • Monitor Windows Security event logs on the ARM server for token manipulation, service creation (Event ID 7045), and new logon sessions using the ARM service account
  • Correlate network telemetry on ARM listening ports for malformed payloads or bursts of connections from non-administrative hosts

Monitoring Recommendations

  • Ingest ARM host logs, network flow, and Active Directory audit events into a centralized SIEM for cross-source correlation
  • Alert on any interactive or remote code execution activity performed under the ARM service account outside change windows
  • Track outbound connections from ARM servers and treat any egress to non-corporate destinations as high priority

How to Mitigate CVE-2024-23469

Immediate Actions Required

  • Upgrade SolarWinds Access Rights Manager to version 2024.3 or later as documented in the vendor release notes
  • Inventory all ARM installations across production, disaster recovery, and lab environments to confirm patch coverage
  • Restrict network reachability of ARM servers to a dedicated management VLAN and known administrative hosts
  • Rotate credentials for the ARM service account and any accounts stored or managed by ARM if compromise is suspected

Patch Information

SolarWinds addressed CVE-2024-23469 in Access Rights Manager 2024.3. Installation instructions and version-specific fix details are published in the SolarWinds ARM 2024.3 Release Notes. Apply the vendor patch rather than relying on compensating controls alone.

Workarounds

  • Segment ARM servers behind firewall rules that block adjacent-network access from user subnets
  • Enforce host-based firewall rules that allow ARM service ports only from named administrator jump hosts
  • Disable or shut down ARM services on hosts that cannot be patched immediately until the upgrade is applied
bash
# Example Windows Firewall rule restricting ARM management port to a jump host
New-NetFirewallRule -DisplayName "ARM-Restrict-Mgmt" `
  -Direction Inbound `
  -Action Allow `
  -Protocol TCP `
  -LocalPort <arm_service_port> `
  -RemoteAddress <jump_host_ip>

# Block all other sources to the same port
New-NetFirewallRule -DisplayName "ARM-Block-Other" `
  -Direction Inbound `
  -Action Block `
  -Protocol TCP `
  -LocalPort <arm_service_port>

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.