Path Restriction Bypass Vulnerability in Serv-U by SolarWinds
CVE-2025-40549
9.1CRITICAL
What is CVE-2025-40549?
A Path Restriction Bypass vulnerability in Serv-U allows an attacker with administrative access to execute arbitrary code within specific directories. This exploit leverages the way server paths and user home directories are handled, enabling privileged users to manipulate file accessibility in a manner that breaches the intended security model. The issue underscores the importance of strict directory management and the potential risks associated with admin privileges in file transfer applications on Windows systems.
Affected Version(s)
Serv-U Windows SolarWinds Serv-U 15.5.2 and prior versions