A type confusion vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to execute arbitrary native code as privileged account. This issue requires administrative privileges to abuse. On Windows deployments, the risk is scored as a medium because services frequently run under less-privileged service accounts by default.
The vulnerability consists of improper type conversion (type confusion) within Serv-U, which allows an attacker to trick the application about the actual type of processed data. This results in the possibility of executing arbitrary native code (native code execution) with the privileges of the account on which the service is running. Exploitation of the vulnerability requires having administrative privileges in the application. On Windows systems, default configurations with less privileged service accounts limit the practical scope of the attack.
An attacker with administrative privileges can execute arbitrary native code in the context of a privileged account, which may lead to complete system takeover, data leakage, and violation of service integrity and availability.
SolarWinds Serv-U should be updated to version 15.5.4 or later according to the information contained in the vendor's release notes (Serv-U 15.5.4 Release Notes). It is also recommended to apply the principle of least privilege for service accounts, especially on Windows systems.
SolarWinds Serv-U — versions prior to 15.5.4 (according to vendor references)
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HSolarwinds Serv U
APPSolarwinds< 15.5.4
Related vulnerabilities
RCE w SolarWinds Serv-U — podatność Remote Memory Escape
SolarWinds Serv-U: IDOR umożliwiający RCE jako root
SolarWinds Serv-U — zdalne wykonanie kodu jako root (RCE)
SolarWinds Serv-U: IDOR umożliwiający privilege escalation i RCE jako root
SolarWinds Serv-U: privilege escalation administratora domeny do systemu