Executive brief
SolarWinds Serv-U Managed File Transfer and Secure FTP are vulnerable to a remote memory escape vulnerability that allows for remote code execution. An unauthenticated attacker can exploit this to gain privileged access to the host machine.
Affected products
- SolarWinds Serv-U Managed File Transfer before 15.2.3 HF2
- SolarWinds Serv-U Secure FTP before 15.2.3 HF2
Timeline
- 2021-07-13: disclosed: Microsoft blog post regarding discovery of threat actor targeting Serv-U with 0-day exploit
- 2021-07-14: patched: NVD Published Date and SolarWinds advisory release
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog