« Back to list

Solarwinds

Solarwinds Dameware Mini Remote Control: vulnerabilities and CVEs

Solarwinds Dameware Mini Remote Control has 8 published vulnerabilities, 0 of them in the last 12 months. 2 are rated critical and 0 are listed by CISA as actively exploited.

CVEs8
Last 12 months0
Critical2
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2025-26396High (7.8)0.23%—Jun 2, 2025
The SolarWinds Dameware Mini Remote Control was determined to be affected by Incorrect Permissions Local Privilege Escalation Vulnerability. This vulnerability requires local access and a valid low privilege account to…
CVE-2021-31217Critical (9.1)4.0%—Jul 13, 2021
In SolarWinds DameWare Mini Remote Control Server 12.0.1.200, insecure file permissions allow file deletion as SYSTEM.
CVE-2019-3980Critical (9.8)5.1%—Oct 8, 2019
The Solarwinds Dameware Mini Remote Client agent v12.1.0.89 supports smart card authentication which can allow a user to upload an executable to be executed on the DWRCS.exe host. An unauthenticated, remote attacker can…
CVE-2019-3957High (7.4)26%—Jun 7, 2019
Dameware Remote Mini Control version 12.1.0.34 and prior contains an unauthenticated remote buffer over-read due to the server not properly validating RsaSignatureLen during key negotiation, which could crash the…
CVE-2019-9017High (7.5)19%—May 2, 2019
DWRCC in SolarWinds DameWare Mini Remote Control 10.0 x64 has a Buffer Overflow associated with the size field for the machine name.
CVE-2018-12897High (7.8)1.7%—Sep 7, 2018
SolarWinds DameWare Mini Remote Control before 12.1 has a Buffer Overflow.
CVE-2015-8220High (7.5)4.8%—Nov 17, 2015
Stack-based buffer overflow in the URI handler in DWRCC.exe in SolarWinds DameWare Mini Remote Control before 12.0 HotFix 1 allows remote attackers to execute arbitrary code via a crafted commandline argument in a link.
CVE-2004-1852Medium (5)0.84%—Mar 23, 2004
DameWare Mini Remote Control 3.x before 3.74 and 4.x before 4.2 transmits the Blowfish encryption key in plaintext, which allows remote attackers to gain sensitive information.

🎯 How it gets exploited (ATT&CK techniques)

  1. T1068 Exploitation for Privilege Escalation1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Solarwinds