Path Restriction Bypass Vulnerability in Serv-U by SolarWinds
CVE-2025-40549

9.1CRITICAL

Key Information:

Vendor

Solarwinds

Status
Vendor
CVE Published:
18 November 2025

What is CVE-2025-40549?

A Path Restriction Bypass vulnerability in Serv-U allows an attacker with administrative access to execute arbitrary code within specific directories. This exploit leverages the way server paths and user home directories are handled, enabling privileged users to manipulate file accessibility in a manner that breaches the intended security model. The issue underscores the importance of strict directory management and the potential risks associated with admin privileges in file transfer applications on Windows systems.

Affected Version(s)

Serv-U Windows SolarWinds Serv-U 15.5.2 and prior versions

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Maurice Moss
.
CVE-2025-40549 : Path Restriction Bypass Vulnerability in Serv-U by SolarWinds