CRITICAL🇵🇱 Wersja polska

CVE-2025-40539

CVSS 9.1v3.1pub. 2026-02-24

A type confusion vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to execute arbitrary native code as privileged account. This issue requires administrative privileges to abuse. On Windows deployments, the risk is scored as a medium because services frequently run under less-privileged service accounts by default.

🤖 AI Analysis
How it works

The vulnerability consists of improper type conversion (type confusion) within Serv-U, which allows an attacker to trick the application about the actual type of processed data. This results in the possibility of executing arbitrary native code (native code execution) with the privileges of the account on which the service is running. Exploitation of the vulnerability requires having administrative privileges in the application. On Windows systems, default configurations with less privileged service accounts limit the practical scope of the attack.

Impact

An attacker with administrative privileges can execute arbitrary native code in the context of a privileged account, which may lead to complete system takeover, data leakage, and violation of service integrity and availability.

Mitigation & patch

SolarWinds Serv-U should be updated to version 15.5.4 or later according to the information contained in the vendor's release notes (Serv-U 15.5.4 Release Notes). It is also recommended to apply the principle of least privilege for service accounts, especially on Windows systems.

Who is affected

SolarWinds Serv-U — versions prior to 15.5.4 (according to vendor references)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
  • Solarwinds Serv U

    APP
    Solarwinds
    < 15.5.4
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2021-35211CRITICAL9.0⚠ KEVPL ✓same product

RCE w SolarWinds Serv-U — podatność Remote Memory Escape

CVE-2026-28305CRITICAL9.1PL ✓same product

SolarWinds Serv-U: IDOR umożliwiający RCE jako root

CVE-2026-28304CRITICAL9.1PL ✓same product

SolarWinds Serv-U — zdalne wykonanie kodu jako root (RCE)

CVE-2026-28302CRITICAL9.1PL ✓same product

SolarWinds Serv-U: IDOR umożliwiający privilege escalation i RCE jako root

CVE-2026-28306CRITICAL9.1PL ✓same product

SolarWinds Serv-U: privilege escalation administratora domeny do systemu