Network Management

SolarWinds Platform Security Concern – CVE-2008-3842 and CVE-2008-3843 in IIS/ASP.NET

Some customers have raised concerns about vulnerabilities CVE-2008-3842 and CVE-2008-3843, which are associated with Microsoft IIS and ASP.NET. These components are required for the SolarWinds Platform to function. Customers may ask if they can uninstall these components or seek guidance on mitigating risks related to these vulnerabilities.

First published date

3/10/2025 1:22 AM

Last published date

4/29/2026 3:15 PM

Overview

SolarWinds relies on Microsoft IIS and ASP.NET as part of its platform infrastructure. Security vulnerabilities such as CVE-2008-3842 and CVE-2008-3843 were identified in 2008, affecting specific versions of ASP.NET. These vulnerabilities could allow remote attackers to execute arbitrary code or cause a denial of service (DoS) attack under certain conditions.

 

SolarWinds does not develop IIS or ASP.NET, as these are Microsoft-managed components. Ensuring their security is the responsibility of system administrators managing Windows Server environments. Uninstalling IIS or ASP.NET is not a viable option, as these components are essential to the operation of the SolarWinds Platform.

 

To mitigate risks, SolarWinds recommends that customers ensure they are running the latest Windows Server and .NET Framework updates and follow industry best practices for securing IIS.

Product section

Network Performance Monitor

Cause

The issue arises from outdated or misconfigured installations of IIS and ASP.NET, specifically:

  • Running an unsupported or vulnerable version of IIS or ASP.NET
  • Lack of latest Microsoft security patches for IIS and ASP.NET
  • Insecure IIS configurations that expose the server to potential attacks

Resolution

1. Ensure the system is updated

  • Verify that your Windows Server, IIS, and .NET Framework are updated with the latest Microsoft security patches.
  • Check Microsoft’s official security bulletins for any additional updates related to IIS and ASP.NET.

2. Follow SolarWinds' security best practices

  • Review the SolarWinds Secure Configuration Guide for hardening recommendations.
  • Ensure HTTPS is enforced, and secure cookies are enabled.
  • Review IIS request filtering settings to restrict unwanted traffic.

3. Consult Microsoft documentation for IIS and ASP.NET security

  • Since IIS and ASP.NET are Microsoft-owned components, customers should follow Microsoft's recommendations for securing their environment.
  • If the customer identifies that SolarWinds specifically exposes or triggers the vulnerabilities, they should provide evidence or security logs to allow SolarWinds Support to investigate further.

Additional Notes:

  • Uninstalling IIS or ASP.NET is not supported, as these are required components for the SolarWinds Platform.
  • If a customer believes their system is at risk, they should work with their system administrator or security team to assess the impact and implement appropriate mitigations.