ZeroHour
The Recordpublished ()ingested

Microsoft discovers SolarWinds zero

criticalExploit / PoC exploited in the wildimportance 60CVE-2021-35211CVE-2021-53211

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-35211
Unauthenticated RCE (Remote Memory Escape) in SolarWinds Serv-U

Microsoft researchers discovered a remote code execution flaw in SolarWinds Serv-U, an out-of-bounds write (CWE-787) described as a "Remote Memory Escape" in the Windows-based Serv-U products. A remote, unauthenticated attacker can trigger the flaw over the network against servers running a version before 15.2.3 HF2 and gain privileged access to the machine hosting Serv-U, with a maximum CVSS 10.0 score reflecting no required privileges, no user interaction, and impact beyond the application's security scope. Both Serv-U Managed File Transfer and Serv-U Secure FTP for Windows are affected. The vulnerability has been exploited in the wild: Microsoft attributed July 2021 attacks exploiting the Serv-U zero-day to Chinese threat actors, later warned of an uptick in exploitation attempts, and the flaw was added to CISA KEV on 2021-11-03 with known ransomware use.

Do: Upgrade Serv-U to 15.2.3 Hotfix 2 (HF2) or later per SolarWinds' instructions immediately, as the flaw is in CISA KEV with known exploitation including ransomware use. Audit Serv-U servers and their logs for signs of exploitation or compromise, and restrict internet exposure of Serv-U/FTP and SSH ports to trusted parties.

10.091% KEV ransomware
  • SolarWinds Serv-U Managed File Transfer (Windows) before 15.2.3 HF2
  • SolarWinds Serv-U Secure FTP (Windows) before 15.2.3 HF2
largeestimated tens of thousands of Serv-U deployments worldwide, with a few thousand instances directly internet-exposed

Indicators of compromiseAll →

TypeIndicatorContext
ipv4208.113.35.58ir SSH port online. We detected mass scanning activity from 208.113.35.58 () between 2021-05-28T08:54:22Z and 2021-05-28T16:02:45Z. B
Full article294 words · extracted from therecord.media · click to collapse

US software company SolarWinds has released security updates on Saturday to patch a vulnerability in its Serv-U file transferring technology that is being actively exploited in the wild.

The attacks and the vulnerability were discovered by Microsoft, SolarWinds said in a security advisory published over the weekend.

Tracked as CVE-2021-35211, the vulnerability is a remote code execution (RCE) bug that can be exploited via the SSH protocol to run malicious code with elevated privileges on SolarWinds applications.

The Texas-based company said the vulnerable Serv-U technology was only included with the Serv-U Managed File Transfer and Serv-U Secure FTP products and that no other SolarWinds application is affected.

  • Neither SolarWinds nor Microsoft said when the attacks abusing CVE-2021-53211 started nor who was behind them.
  • A Serv-U hotfix was released on Friday, July 9, 2021 — v15.2.3 HF2.
  • SolarWinds shared some indicators of compromise (IOCs) related to the attacks in its security advisory. We will not be reproducing them here in case SolarWinds updates the IOCs.
  • All Serv-U versions prior to v15.2.3 HF2, released on Friday, are vulnerable to attacks.
  • Disabling SSH access on the two affected products prevents exploitation.
  • According to a Censys search query, there are more than 8,200 SolarWinds Serv-U systems exposing their SSH port online.

We detected mass scanning activity from 208.113.35.58 () between 2021-05-28T08:54:22Z and 2021-05-28T16:02:45Z.

Basic web scan targeting port 443/tcp – no exploit attempt or payload. Assuming it was a recon scan in this case. pic.twitter.com/Zm31JF4xFS

— Bad Packets (@bad_packets) July 13, 2021

No previous article

No new articles

Catalin Cimpanu

is a cybersecurity reporter who previously worked at ZDNet and Bleeping Computer, where he became a well-known name in the industry for his constant scoops on new vulnerabilities, cyberattacks, and law enforcement actions against hackers.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/microsoft-discovers-a-solarwinds-zero-day-exploited-in-the-wild