Solarwinds
Solarwinds Dameware Mini Remote Control: vulnerabilities and CVEs
Solarwinds Dameware Mini Remote Control has 8 published vulnerabilities, 0 of them in the last 12 months. 2 are rated critical and 0 are listed by CISA as actively exploited.
CVEs8
Last 12 months0
Critical2
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-26396 | High (7.8) | 0.23% | — | Jun 2, 2025 | The SolarWinds Dameware Mini Remote Control was determined to be affected by Incorrect Permissions Local Privilege Escalation Vulnerability. This vulnerability requires local access and a valid low privilege account to… |
| CVE-2021-31217 | Critical (9.1) | 4.0% | — | Jul 13, 2021 | In SolarWinds DameWare Mini Remote Control Server 12.0.1.200, insecure file permissions allow file deletion as SYSTEM. |
| CVE-2019-3980 | Critical (9.8) | 5.1% | — | Oct 8, 2019 | The Solarwinds Dameware Mini Remote Client agent v12.1.0.89 supports smart card authentication which can allow a user to upload an executable to be executed on the DWRCS.exe host. An unauthenticated, remote attacker can… |
| CVE-2019-3957 | High (7.4) | 26% | — | Jun 7, 2019 | Dameware Remote Mini Control version 12.1.0.34 and prior contains an unauthenticated remote buffer over-read due to the server not properly validating RsaSignatureLen during key negotiation, which could crash the… |
| CVE-2019-9017 | High (7.5) | 19% | — | May 2, 2019 | DWRCC in SolarWinds DameWare Mini Remote Control 10.0 x64 has a Buffer Overflow associated with the size field for the machine name. |
| CVE-2018-12897 | High (7.8) | 1.7% | — | Sep 7, 2018 | SolarWinds DameWare Mini Remote Control before 12.1 has a Buffer Overflow. |
| CVE-2015-8220 | High (7.5) | 4.8% | — | Nov 17, 2015 | Stack-based buffer overflow in the URI handler in DWRCC.exe in SolarWinds DameWare Mini Remote Control before 12.0 HotFix 1 allows remote attackers to execute arbitrary code via a crafted commandline argument in a link. |
| CVE-2004-1852 | Medium (5) | 0.84% | — | Mar 23, 2004 | DameWare Mini Remote Control 3.x before 3.74 and 4.x before 4.2 transmits the Blowfish encryption key in plaintext, which allows remote attackers to gain sensitive information. |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.