CVE-2021-35211: SolarWinds Serv-U Remote Code Execution Vulnerability
Microsoft discovered a remote code execution (RCE) vulnerability in the SolarWinds Serv-U product utilizing a Remote Memory Escape Vulnerability. If exploited, a threat actor may be able to gain privileged access to the machine hosting Serv-U Only. SolarWinds Serv-U Managed File Transfer and Serv-U Secure FTP for Windows before 15.2.3 HF2 are affected by this vulnerability.
Other sources
SolarWinds Serv-U contains an unspecified memory escape vulnerability which can allow for remote code execution.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SolarWinds Serv-Uto a version that resolves this vulnerability.Fixed in 15.2.3 HF2
Event History
Frequently Asked Questions
What is CVE-2021-35211?
CVE-2021-35211 is a remote code execution (RCE) vulnerability in SolarWinds Serv-U product.
What is the severity of CVE-2021-35211?
CVE-2021-35211 has a severity value of 10, which is classified as critical.
How does CVE-2021-35211 impact SolarWinds Serv-U?
If exploited, CVE-2021-35211 allows a threat actor to gain privileged access to the machine hosting Serv-U Only.
Which versions of SolarWinds Serv-U are affected by CVE-2021-35211?
Versions up to and including 15.2.3 of SolarWinds Serv-U are affected by CVE-2021-35211.
How can I fix CVE-2021-35211?
To fix CVE-2021-35211, update to a version of SolarWinds Serv-U that is higher than 15.2.3.