CVE-2025-40540: SolarWinds Serv-U Type Confusion Remote Code Execution Vulnerability
A type confusion vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to execute arbitrary native code as privileged account.
This issue requires administrative privileges to abuse. On Windows deployments, the risk is scored as a medium because services frequently run under less-privileged service accounts by default.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-40540?
CVE-2025-40540 is rated as a high-severity vulnerability due to its potential for remote code execution with privileged access.
How do I fix CVE-2025-40540?
To fix CVE-2025-40540, it is recommended to update SolarWinds Serv-U to the latest patched version provided by the vendor.
What causes CVE-2025-40540?
CVE-2025-40540 is caused by a type confusion vulnerability in the way SolarWinds Serv-U processes certain inputs.
Who is affected by CVE-2025-40540?
Administrators using vulnerable versions of SolarWinds Serv-U are affected by CVE-2025-40540.
What are the potential impacts of CVE-2025-40540?
The potential impacts of CVE-2025-40540 include unauthorized remote code execution resulting in a complete system compromise.