Logic Error Vulnerability in Serv-U by SolarWinds
CVE-2025-40547
9.1CRITICAL
What is CVE-2025-40547?
A logic error vulnerability exists in Serv-U that may allow attackers with administrative access to execute code maliciously. This vulnerability is dependent on having admin privileges, making it a serious concern for system administrators. On Windows deployments, the impact is mitigated as services typically operate under lower-privileged accounts. Administrators must be vigilant and ensure prompt updates to minimize exposure to potential exploits.
Affected Version(s)
Serv-U Windows SolarWinds Serv-U 15.5.2 and prior versions
References
CVSS V3.1
Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
SolarWinds would like to thank researchers working with Intigriti on our bug bounty program