#VU51827 Deserialization of Untrusted Data in Orion Virtual Infrastructure Monitor - CVE-2021-27277
Published: March 31, 2021
Orion Virtual Infrastructure Monitor
SolarWinds
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to insecure input validation when processing serialized data in the OneTimeJobSchedulerEventsService WCF service. A local user can pass specially crafted data to the application and execute arbitrary code on the target system with elevated privileges.