First published: Wed Jul 14 2021(Updated: )
Microsoft discovered a remote code execution (RCE) vulnerability in the SolarWinds Serv-U product utilizing a Remote Memory Escape Vulnerability. If exploited, a threat actor may be able to gain privileged access to the machine hosting Serv-U Only. SolarWinds Serv-U Managed File Transfer and Serv-U Secure FTP for Windows before 15.2.3 HF2 are affected by this vulnerability.
Credit: psirt@solarwinds.com psirt@solarwinds.com psirt@solarwinds.com
Affected Software | Affected Version | How to fix |
---|---|---|
SolarWinds Serv-U | <15.2.3 | |
SolarWinds Serv-U | =15.2.3 | |
SolarWinds Serv-U | =15.2.3-hotfix1 | |
SolarWinds Serv-U | ||
<15.2.3 | ||
=15.2.3 | ||
=15.2.3-hotfix1 |
SolarWinds has released a hotfix 15.2.3 HF2 It is suggested to upgrade to the latest hotfix as soon as possible
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-35211 is a remote code execution (RCE) vulnerability in SolarWinds Serv-U product.
CVE-2021-35211 has a severity value of 10, which is classified as critical.
If exploited, CVE-2021-35211 allows a threat actor to gain privileged access to the machine hosting Serv-U Only.
Versions up to and including 15.2.3 of SolarWinds Serv-U are affected by CVE-2021-35211.
To fix CVE-2021-35211, update to a version of SolarWinds Serv-U that is higher than 15.2.3.