ZeroHour

CVE-2021-35211

KEV ransomwarelarge1

Unauthenticated RCE (Remote Memory Escape) in SolarWinds Serv-U

CISA: SolarWinds Serv-U Remote Code Execution Vulnerability

CVSS 3.1
10.0 critical
EPSS
91%p100
Published
()
KEV added
AI analysis

Microsoft researchers discovered a remote code execution flaw in SolarWinds Serv-U, an out-of-bounds write (CWE-787) described as a "Remote Memory Escape" in the Windows-based Serv-U products. A remote, unauthenticated attacker can trigger the flaw over the network against servers running a version before 15.2.3 HF2 and gain privileged access to the machine hosting Serv-U, with a maximum CVSS 10.0 score reflecting no required privileges, no user interaction, and impact beyond the application's security scope. Both Serv-U Managed File Transfer and Serv-U Secure FTP for Windows are affected. The vulnerability has been exploited in the wild: Microsoft attributed July 2021 attacks exploiting the Serv-U zero-day to Chinese threat actors, later warned of an uptick in exploitation attempts, and the flaw was added to CISA KEV on 2021-11-03 with known ransomware use.

What to do: Upgrade Serv-U to 15.2.3 Hotfix 2 (HF2) or later per SolarWinds' instructions immediately, as the flaw is in CISA KEV with known exploitation including ransomware use. Audit Serv-U servers and their logs for signs of exploitation or compromise, and restrict internet exposure of Serv-U/FTP and SSH ports to trusted parties.

Affected
SolarWinds Serv-U Managed File Transfer (Windows)before 15.2.3 HF2
SolarWinds Serv-U Secure FTP (Windows)before 15.2.3 HF2
Estimated exposure
largeestimated tens of thousands of Serv-U deployments worldwide, with a few thousand instances directly internet-exposed — Serv-U is a long-established enterprise managed file-transfer/FTP server commonly deployed for external file exchange, and public internet scans around the time of disclosure showed thousands of exposed Serv-U instances; exact counts are…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Microsoft discovered a remote code execution (RCE) vulnerability in the SolarWinds Serv-U product utilizing a Remote Memory Escape Vulnerability. If exploited, a threat actor may be able to gain privileged access to the machine hosting Serv-U Only. SolarWinds Serv-U Managed File Transfer and Serv-U Secure FTP for Windows before 15.2.3 HF2 are affected by this vulnerability.

CISA Known Exploited Vulnerability
Affected
SolarWinds Serv-U
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
solarwinds
Products
serv-u
Weakness
CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news