CVE-2025-40547: SolarWinds Serv-U Logic Abuse - Remote Code Execution Vulnerability
A logic error vulnerability exists in Serv-U which when abused could give a malicious actor with access to admin privileges the ability to execute code.
This issue requires administrative privileges to abuse. On Windows deployments, the risk is scored as a medium because services frequently run under less-privileged service accounts by default.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-40547?
The severity of CVE-2025-40547 is considered medium for Windows deployments.
How can I fix CVE-2025-40547?
To fix CVE-2025-40547, ensure that you apply the latest patches and updates provided by SolarWinds for Serv-U.
Who is affected by CVE-2025-40547?
CVE-2025-40547 affects users of SolarWinds Serv-U with administrative privileges.
What type of vulnerability is CVE-2025-40547?
CVE-2025-40547 is categorized as a logic error vulnerability.
What impact does CVE-2025-40547 have?
Exploitation of CVE-2025-40547 could allow a malicious actor with admin access to execute arbitrary code.