CVE-2019-3980Exploit(solarwinds / dameware_mini_remote_control)

HIGHCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for solarwinds dameware_mini_remote_control systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

The Solarwinds Dameware Mini Remote Client agent v12.1.0.89 supports smart card authentication which can allow a user to upload an executable to be executed on the DWRCS.exe host. An unauthenticated, remote attacker can request smart card login and upload and execute an arbitrary executable run under the Local System account.

7.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-346

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dameware_mini_remote_control

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
dameware_mini_remote_control

1 version affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-06: 1PoC Mentioned / Linked · 2026-03-06: 1Exploit Tool / Code · 2026-03-06: 1Active Exploitation · 2026-03-06: 1Technical Details · 2026-03-06: 103-06
Signal classification1 categories
Exploit
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • David Boyd@fir3d0g
    Exploit

    We are still seeing this on engagements, so I wrote a tool. DameFlare is a Python 3 exploit for CVE-2019-3980. Unauthenticated RCE as SYSTEM via smart card auth bypass. Full credit to @TenableSecurity for the original research/POC. https://github.com/boydhacks/dameflare

    Post summary

    The post shares the DameFlare Python 3 exploit for CVE‑2019‑3980, notes it is being used in live engagements, and links to the code repository.

    01181680
    2.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsolarwindsdameware_mini_remote_control12.1.0.89--

Explore more