Microsoft stated that it discovered a remote code execution (RCE) vulnerability (with a CVSS 3.1 score of 10.0) in the SolarWinds Serv-U product utilizing a Remote Memory Escape Vulnerability.
This is a zero-day vulnerability and if exploited, a threat actor may be able to gain privileged access to the machine hosting Serv-U Only. Even though no exploit regarding this vulnerability has been discovered, due to its severity/criticality, it is highly recommended that the following patches are downloaded to ensure the safety of systems/assets.
Affected Systems
The following servers/systems are affected by this vulnerability;
IoC’s
Recommended Solution(s)
Organizations are recommended to update their instances of Serv-U to the latest available version.
Product | Article | Patch |
---|---|---|
SolarWinds Serv-U Managed File Transfer
Serv-U Secure FTP for Windows before 15.2.3 HF2 |
Article | Security Update |
CVE / CWE
CVE-2021-35211
Related Website(s)
* Vulnerabilities with a CVSS 3.1 score between 7.0 and 8.9 are evaluated to be “high” whereas vulnerabilities with a CVSS 3.1 score between 9.0 and 10.0 are evaluated to be “critical”.
+90 216 504 53 32
Aydınevler Mahallesi,İsmet İnönü Cadddesi,Küçükyalı Ofis Park A Blok,No:20/1 Maltepe İstanbul
+90 312 235 44 51
You can register to our newsletter on the home page to be instantly informed about security vulnerabilities.