SolarWinds patches zero-day exploited in the wild (CVE-2021-35211)
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-35211 | Unauthenticated RCE (Remote Memory Escape) in SolarWinds Serv-U Microsoft researchers discovered a remote code execution flaw in SolarWinds Serv-U, an out-of-bounds write (CWE-787) described as a "Remote Memory Escape" in the Windows-based Serv-U products. A remote, unauthenticated attacker can trigger the flaw over the network against servers running a version before 15.2.3 HF2 and gain privileged access to the machine hosting Serv-U, with a maximum CVSS 10.0 score reflecting no required privileges, no user interaction, and impact beyond the application's security scope. Both Serv-U Managed File Transfer and Serv-U Secure FTP for Windows are affected. The vulnerability has been exploited in the wild: Microsoft attributed July 2021 attacks exploiting the Serv-U zero-day to Chinese threat actors, later warned of an uptick in exploitation attempts, and the flaw was added to CISA KEV on 2021-11-03 with known ransomware use. Do: Upgrade Serv-U to 15.2.3 Hotfix 2 (HF2) or later per SolarWinds' instructions immediately, as the flaw is in CISA KEV with known exploitation including ransomware use. Audit Serv-U servers and their logs for signs of exploitation or compromise, and restrict internet exposure of Serv-U/FTP and SSH ports to trusted parties. | 10.0 | 91% | KEV ransomware |
| largeestimated tens of thousands of Serv-U deployments worldwide, with a few thousand instances directly internet-exposed |
Full article391 words · extracted from helpnetsecurity.com · click to collapse
SolarWinds has released an emergency patch for CVE-2021-35211, a RCE vulnerability affecting its Serv-U Managed File Transfer and Serv-U Secure FTP that is currently being exploited in the wild.

“Microsoft has provided evidence of limited, targeted customer impact, though SolarWinds does not currently have an estimate of how many customers may be directly affected by the vulnerability. SolarWinds is unaware of the identity of the potentially affected customers,” the company shared.
Microsoft has also shared a proof-of-concept exploit with SolarWinds, but no PoCs are publicly available at this time.
About CVE-2021-35211
CVE-2021-35211 was unearthed in the SolarWinds Serv-U product by Microsoft’s Threat Intelligence Center (MSTIC) and Microsoft Offensive Security Research teams.
SolarWinds said they will be publishing additional details about the vulnerability once its customers have had enough time to implement the fix. In the meantime, we know that:
- It affects Serv-U 15.2.3 HF1 and all prior Serv-U versions – but does not exist if SSH is enabled for a Serv-U installation
- Allows attackers to perform remote code execution and to then install programs; view, change, or delete data; or run programs on the affected system
- Is not related to the SUNBURST supply chain attack
The company has shared some indicators of attack and other helpful information enterprise security teams can use to check whether their installations have been targeted.
Censys CTO Derek Abdine said they discovered over 8,000 Serv-U hosts on the internet, and also that a lot of those “present the same SSH host key fingerprint (which Serv-U exposes for SCP)”.
This thread has already become a monster, so I'm going to stop here and pull my thoughts into a blog post. But, we learned that there are a ton of Serv-U hosts sharing the same SSH private/public keys, rendering encrypted key exchange over SCP useless for these hosts (think mitm)
— Derek Abdine (@dabdine) July 13, 2021
UPDATE (July 14, 2021, 01:10 a.m. PT):
Microsoft has attributed these “limited and targeted attacks” to DEV-0322, which is targeting entities in the U.S. Defense Industrial Base Sector and software companies.
“This activity group is based in China and has been observed using commercial VPN solutions and compromised consumer routers in their attacker infrastructure,” they shared. The company has provided advice for organizations on how to check whether they have been targeted / their Serv-U installations have been compromised.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2021/07/13/solarwinds-patches-zero-day-exploited-in-the-wild-cve-2021-35211/