Application Privilege Escalation in SolarWinds Serv-U | The Missing Link

Discovered by Chris Moberly on behalf of The Missing Link Security

Vulnerability Details

SolarWinds Serv-U FTP Server is vulnerable to privilege escalation from remote authenticated users by leveraging the CSV user import function. This leads to obtaining remote code execution under the context of the Windows SYSTEM account in a default installation.

Affected Versions

Discovered in: 15.1.6 (current as of August 2018)
Fixed in: Serv-U 15.1.6 Hotfix 2

Latest News