Code Execution Vulnerability in Serv-U by SolarWinds
CVE-2025-40548

9.1CRITICAL

Key Information:

Vendor

Solarwinds

Status
Vendor
CVE Published:
18 November 2025

What is CVE-2025-40548?

A vulnerability exists in Serv-U that allows a malicious user with administrative access to execute arbitrary code. This flaw arises from a missing validation process, presenting a risk if exploited. Although this issue needs administrative privileges to be abused, it particularly affects environments where services run under less privileged accounts on Windows, potentially increasing exposure to risks. Organizations are urged to review their security configurations and implement necessary patches.

Affected Version(s)

Serv-U Windows SolarWinds Serv-U 15.5.2 and prior versions

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

SolarWinds would like to thank researchers working with Intigriti on our bug bounty program
.
CVE-2025-40548 : Code Execution Vulnerability in Serv-U by SolarWinds