Microsoft discovered a remote code execution (RCE) vulnerability in the SolarWinds Serv-U product utilizing a Remote Memory Escape Vulnerability. If exploited, a threat actor may be able to gain privileged access to the machine hosting Serv-U Only. SolarWinds Serv-U Managed File Transfer and Serv-U Secure FTP for Windows before 15.2.3 HF2 are affected by this vulnerability.
2021-07-14T21:15:08.090
2025-03-12T20:58:10.867
Analyzed
CVSSv3.1: 9.0 (CRITICAL)
AV:N/AC:L/Au:N/C:C/I:C/A:C
10.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | solarwinds | serv-u | < 15.2.3 | Yes |
Application | solarwinds | serv-u | 15.2.3 | Yes |
Application | solarwinds | serv-u | 15.2.3 | Yes |