Junglewise Threat Intelligence

CVE-2021-35211: SolarWinds Serv-U Remote Code Execution Vulnerability

CVE-2021-35211 · Severity: critical · CVSS 10 · Exploited in the wild · Published 2021-11-03

Technologies: SolarWinds Serv-U. Vendors: SolarWinds.

Executive brief

SolarWinds Serv-U Managed File Transfer and Secure FTP are vulnerable to a remote memory escape vulnerability that allows for remote code execution. An unauthenticated attacker can exploit this to gain privileged access to the host machine.

Affected products

  • SolarWinds Serv-U Managed File Transfer before 15.2.3 HF2
  • SolarWinds Serv-U Secure FTP before 15.2.3 HF2

Timeline

  • 2021-07-13: disclosed: Microsoft blog post regarding discovery of threat actor targeting Serv-U with 0-day exploit
  • 2021-07-14: patched: NVD Published Date and SolarWinds advisory release
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats