← Back to CVE List

CVE-2019-8917

Published: 2019-02-18T19:29Z
Last Modified: 2024-11-21T04:50Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
SolarWinds Orion NPM before 12.4 suffers from a SYSTEM remote code execution vulnerability in the OrionModuleEngine service. This service establishes a NetTcpBinding endpoint that allows remote, unauthenticated clients to connect and call publicly exposed methods. The InvokeActionMethod method may be abused by an attacker to execute commands as the SYSTEM user. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt