Solarwinds
Solarwinds Dameware Mini Remote Control: vulnerabilidades y CVE
Solarwinds Dameware Mini Remote Control tiene 8 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE8
Últimos 12 meses0
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-26396 | Alta (7.8) | 0.23% | — | 2 jun 2025 | The SolarWinds Dameware Mini Remote Control was determined to be affected by Incorrect Permissions Local Privilege Escalation Vulnerability. This vulnerability requires local access and a valid low privilege account to… |
| CVE-2021-31217 | Crítica (9.1) | 4.0% | — | 13 jul 2021 | In SolarWinds DameWare Mini Remote Control Server 12.0.1.200, insecure file permissions allow file deletion as SYSTEM. |
| CVE-2019-3980 | Crítica (9.8) | 5.1% | — | 8 oct 2019 | The Solarwinds Dameware Mini Remote Client agent v12.1.0.89 supports smart card authentication which can allow a user to upload an executable to be executed on the DWRCS.exe host. An unauthenticated, remote attacker can… |
| CVE-2019-3957 | Alta (7.4) | 26% | — | 7 jun 2019 | Dameware Remote Mini Control version 12.1.0.34 and prior contains an unauthenticated remote buffer over-read due to the server not properly validating RsaSignatureLen during key negotiation, which could crash the… |
| CVE-2019-9017 | Alta (7.5) | 19% | — | 2 may 2019 | DWRCC in SolarWinds DameWare Mini Remote Control 10.0 x64 has a Buffer Overflow associated with the size field for the machine name. |
| CVE-2018-12897 | Alta (7.8) | 1.7% | — | 7 sept 2018 | SolarWinds DameWare Mini Remote Control before 12.1 has a Buffer Overflow. |
| CVE-2015-8220 | Alta (7.5) | 4.8% | — | 17 nov 2015 | Stack-based buffer overflow in the URI handler in DWRCC.exe in SolarWinds DameWare Mini Remote Control before 12.0 HotFix 1 allows remote attackers to execute arbitrary code via a crafted commandline argument in a link. |
| CVE-2004-1852 | Media (5) | 0.84% | — | 23 mar 2004 | DameWare Mini Remote Control 3.x before 3.74 and 4.x before 4.2 transmits the Blowfish encryption key in plaintext, which allows remote attackers to gain sensitive information. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.