Path Restriction Bypass Vulnerability in Serv-U by SolarWinds
CVE-2025-40549
9.1CRITICAL
What is CVE-2025-40549?
A Path Restriction Bypass vulnerability in Serv-U allows an attacker with administrative access to execute arbitrary code within specific directories. This exploit leverages the way server paths and user home directories are handled, enabling privileged users to manipulate file accessibility in a manner that breaches the intended security model. The issue underscores the importance of strict directory management and the potential risks associated with admin privileges in file transfer applications on Windows systems.
Affected Version(s)
Serv-U Windows SolarWinds Serv-U 15.5.2 and prior versions
References
CVSS V3.1
Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Maurice Moss