ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

New SolarWinds Serv-U vulnerability targeted in Log4j-related attacks

criticalVulnerability exploited in the wildimportance 60CVE-2021-35247CVE-2021-35211

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-35211
Unauthenticated RCE (Remote Memory Escape) in SolarWinds Serv-U

Microsoft researchers discovered a remote code execution flaw in SolarWinds Serv-U, an out-of-bounds write (CWE-787) described as a "Remote Memory Escape" in the Windows-based Serv-U products. A remote, unauthenticated attacker can trigger the flaw over the network against servers running a version before 15.2.3 HF2 and gain privileged access to the machine hosting Serv-U, with a maximum CVSS 10.0 score reflecting no required privileges, no user interaction, and impact beyond the application's security scope. Both Serv-U Managed File Transfer and Serv-U Secure FTP for Windows are affected. The vulnerability has been exploited in the wild: Microsoft attributed July 2021 attacks exploiting the Serv-U zero-day to Chinese threat actors, later warned of an uptick in exploitation attempts, and the flaw was added to CISA KEV on 2021-11-03 with known ransomware use.

Do: Upgrade Serv-U to 15.2.3 Hotfix 2 (HF2) or later per SolarWinds' instructions immediately, as the flaw is in CISA KEV with known exploitation including ransomware use. Audit Serv-U servers and their logs for signs of exploitation or compromise, and restrict internet exposure of Serv-U/FTP and SSH ports to trusted parties.

10.091% KEV ransomware
  • SolarWinds Serv-U Managed File Transfer (Windows) before 15.2.3 HF2
  • SolarWinds Serv-U Secure FTP (Windows) before 15.2.3 HF2
largeestimated tens of thousands of Serv-U deployments worldwide, with a few thousand instances directly internet-exposed
CVE-2021-35247
Actively Exploited Input Validation Flaw in SolarWinds Serv-U LDAP Login

CVE-2021-35247 is an improper input validation flaw (CWE-20) in the SolarWinds Serv-U web login screen's LDAP authentication path, where submitted characters are not sufficiently sanitized before being passed to the LDAP server. It is triggered remotely over the network with no privileges or user interaction required (CVSS:3.1/AV:N/AC:L/PR:N/UI:N), by sending crafted, non-sanitized characters through the login-to-LDAP flow; SolarWinds notes that LDAP servers ignored the improper characters and no downstream effect was detected, and the 5.3 (medium) CVSS score reflects a low integrity impact with no confidentiality or availability impact. An attacker gains the ability to feed unsanitized input into the LDAP authentication process; no confirmed code execution or full compromise is documented for this specific bug, but it is nevertheless on CISA's Known Exploited Vulnerabilities catalog. Affected organizations are those running SolarWinds Serv-U whose web login screen uses LDAP authentication. Exploitation is confirmed in the wild: CISA added the bug to the KEV catalog on 2022-01-21, Microsoft warned that threat actors attempted to exploit the Serv-U bug in real-world attacks, and reporting on this flaw surfaced alongside the Log4j (Log4Shell) attack wave targeting SolarWinds products.

Do: Schedule an upgrade to the latest SolarWinds Serv-U release, which adds the required input validation and sanitization to the LDAP login path; this is the CISA KEV required action, so KEV deadlines apply. Until patched, restrict access to the Serv-U web login from untrusted networks and review LDAP/authentication logs for suspicious or malformed login input. While updating, also confirm Serv-U is patched for the related critical Serv-U 15.5 root code execution flaws and any Log4j exposure covered in the same reporting cycle.

5.33% KEV
  • SolarWinds Serv-U
moderate≈ several thousand internet-exposed Serv-U servers (estimate; no scan counts in source data)
Full article325 words · extracted from helpnetsecurity.com · click to collapse

Attackers looking to exploit recently discovered Log4j vulnerabilities are also trying to take advantage of a previously undisclosed vulnerability in the SolarWinds Serv-U software (CVE-2021-35247).

It affects version 15.2.5 and previous versions of Serv-U, and has been patched by SolarWinds in version 15.3.

CVE-2021-35247

About CVE-2021-35247

CVE-2021-35247 is an input validation vulnerability in the Serv-U File Server’s web login screen that could allow attackers to build a query after been given some input and send that query over the network without sanitation.

“When hunting for log4j exploit attempt I noticed attacks coming from serv-u.exe. Taking a closer looked revealed you could feed Serv-U with data and it’ll build a LDAP query with your unsanitized input! This could be used for log4j attack attempts, but also for LDAP injection,” shared Microsoft security researcher Jonathan Bar Or.

According to SolarWinds’ security advisory, the vulnerability has been fixed by updating the input mechanism to perform additional validation and sanitization.

“No downstream affect has been detected as the LDAP servers ignored improper characters,” the company also noted, apparently refuting Microsoft researcher’s last conclusion.

Microsoft did not say whether the attackers were successful in exploiting CVE-2021-35247, but have urged customers to apply security updates to vulnerable devices.

This is the second Serv-U vulnerability detected in the last six months getting exploited in the wild. The earlier one was a (at the time) zero-day remote code execution flaw (CVE-2021-35211), and its exploitation has been attributed by Microsoft to a China-based attack group hitting entities in the U.S. defense industrial base sector and software companies.

UPDATE: Friday, January 21, 01:25 PT

A SolarWinds spokesperson reached out with the following comment:

“The activity Microsoft was referring to in their report was related to a threat actor attempting to login to Serv-U using the Log4J vulnerability but that attempt failed as Serv-U does not utilize Log4J code and the target for authentication LDAP (Microsoft Active Directory) is not susceptible to Log4J attacks.”

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2022/01/20/cve-2021-35247/