CRITICAL

CVE-2021-25274

CVSS v3

9.8

CRITICAL

EPSS Score

50.2%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

The Collector Service in SolarWinds Orion Platform before 2020.2.4 uses MSMQ (Microsoft Message Queue) and doesn't set permissions on its private queues. As a result, remote unauthenticated clients can send messages to TCP port 1801 that the Collector Service will process. Additionally, upon processing of such messages, the service deserializes them in insecure manner, allowing remote arbitrary code execution as LocalSystem.

Technical details

Published
2/3/2021

Frequently asked questions

What is CVE-2021-25274?

The Collector Service in SolarWinds Orion Platform before 2020.2.4 uses MSMQ (Microsoft Message Queue) and doesn't set permissions on its private queues. As a result, remote unauthenticated clients can send messages to TCP port 1801 that the Collector Service will process. Additionally, upon processing of such messages, the service deserializes them in insecure manner, allowing remote arbitrary code execution as LocalSystem.

Is CVE-2021-25274 actively exploited?

Active exploitation of CVE-2021-25274 has not been confirmed. The EPSS score is 50.2%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2021-25274?

CVE-2021-25274 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2021-25274 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.