Coming Soon...

Q-CERT website is currently under maintenance. We should be back shortly. Thank you for yor patience.

SolarWinds Serv-U Memory Escape Vulnerability Zero-Day

Issued: 
Wednesday, 14 July, 2021
Last Revision: 
Wednesday, 14 July, 2021
Vendor: 
Product: 
Severity Level: 
Summary: 

SolarWinds was recently notified by Microsoft of a security vulnerability (CVE-2021-35211) related to Serv-U Managed File Transfer Server and Serv-U Secured FTP. The vulnerability exists in the latest Serv-U version 15.2.3 HF1 released May 5, 2021, and all prior versions.  A hotfix to resolve this vulnerability has been published,.

 

A threat actor who successfully exploited this vulnerability could run arbitrary code with privileges. An attacker could then install programs; view, change, or delete data; or run programs on the affected system. Organizations are strongly encouraged to check the Platform and Product(s) version used in their environment and apply relevant patches as soon as possible.

 

Description CVECVSS3.0 Score
Remote Memory Escape VulnerabilityCVE-2021-35211N/A

 

Recommendation: