Skip to main content

Dealing with the SolarWinds Orion compromise

Immediate actions for all organisations using the SolarWinds Orion suite of IT management tools

Art Alex via Getty Images

Last updated

This page was last updated at 11:30 on 08 January 2021.

Enhanced technical guidance is available on the NCSC's Cyber Security Information Sharing Partnership (CiSP) platform.
 

SolarWinds Orion, the popular IT system management platform, has been compromised and may be used for onward attacks against systems connected to the product.

An attacker has been able to add a malicious, unauthorised modification to SolarWinds Orion products which allows them to send administrator-level commands to any affected installation. This modification:

  • causes the Orion products to connect to an attacker-controlled server to request instructions
  • does not rely on the attacker being able to directly connect from the internet to the Orion server

There is evidence of the attacker using this capability in some cases to move from a single Orion server to other parts of the victim’s IT network.

Not all customers who have an installation with the unauthorised, malicious modification will have been seriously affected, but all should take immediate action.

This guidance is liable to change as further information becomes available. If you discover you have a compromised system please check back for updates.







Published

Reviewed

Version

2.0