10

CVE-2021-35211

Warnung
Medienbericht

Serv-U Remote Memory Escape Vulnerability

Microsoft discovered a remote code execution (RCE) vulnerability in the SolarWinds Serv-U product utilizing a Remote Memory Escape Vulnerability. If exploited, a threat actor may be able to gain privileged access to the machine hosting Serv-U Only. SolarWinds Serv-U Managed File Transfer and Serv-U Secure FTP for Windows before 15.2.3 HF2 are affected by this vulnerability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SolarwindsServ-u Version < 15.2.3
SolarwindsServ-u Version15.2.3 Update-
SolarwindsServ-u Version15.2.3 Updatehotfix1

03.11.2021: CISA Known Exploited Vulnerabilities (KEV) Catalog

SolarWinds Serv-U Remote Code Execution Vulnerability

Schwachstelle

SolarWinds Serv-U contains an unspecified memory escape vulnerability which can allow for remote code execution.

Beschreibung

Apply updates per vendor instructions.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 91.16% 0.998
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 10 3.9 6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
psirt@solarwinds.com 9 2.2 6
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
05.06.2026 21:23
https://www.microsoft.com/security/blog/2021/07/13/microsoft-discovers-threat-actor-targeting-solarwinds-serv-u-software-with-0-day-exploit
Patch
Vendor Advisory
https://www.solarwinds.com/trust-center/security-advisories/cve-2021-35211
Patch
Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-35211
US Government Resource