Type Confusion Vulnerability in Serv-U by SolarWinds
CVE-2025-40539
9.1CRITICAL
What is CVE-2025-40539?
A type confusion vulnerability is present in Serv-U, allowing attackers to exploit the flaw to execute arbitrary native code with elevated privileges. This vulnerability necessitates administrative privileges for exploitation. While the potential impact varies, Windows deployments may be at lesser risk since services typically operate under lower-privileged service accounts by default.
Affected Version(s)
Serv-U Windows SolarWinds Serv-U 15.5.3 and prior versions