Logic Error Vulnerability in Serv-U by SolarWinds
CVE-2025-40547

9.1CRITICAL

Key Information:

Vendor

Solarwinds

Status
Vendor
CVE Published:
18 November 2025

What is CVE-2025-40547?

A logic error vulnerability exists in Serv-U that may allow attackers with administrative access to execute code maliciously. This vulnerability is dependent on having admin privileges, making it a serious concern for system administrators. On Windows deployments, the impact is mitigated as services typically operate under lower-privileged accounts. Administrators must be vigilant and ensure prompt updates to minimize exposure to potential exploits.

Affected Version(s)

Serv-U Windows SolarWinds Serv-U 15.5.2 and prior versions

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

SolarWinds would like to thank researchers working with Intigriti on our bug bounty program
.
CVE-2025-40547 : Logic Error Vulnerability in Serv-U by SolarWinds