peter bassill · operator
$ cve CVE-2019-3980 JSON

CVE-2019-3980

9.8
CRITICAL · CVSS 3.1 · EPSS 5.1% (pctl 92)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

The Solarwinds Dameware Mini Remote Client agent v12.1.0.89 supports smart card authentication which can allow a user to upload an executable to be executed on the DWRCS.exe host. An unauthenticated, remote attacker can request smart card login and upload and execute an arbitrary executable run under the Local System account.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS5.14% — more likely to be exploited than 92% of all CVEs
WeaknessCWE-346
On CISA KEVno
Public exploitnone known
Published2019-10-08
Last modified2026-06-17

Affected (1)

VendorProduct
solarwindsdameware mini remote control

References

→ the Explorer  ·  watch your stack  ·  NVD