Path Restriction Bypass Vulnerability in Serv-U by SolarWinds
CVE-2025-40549
What is CVE-2025-40549?
A Path Restriction Bypass vulnerability in Serv-U allows an attacker with administrative access to execute arbitrary code within specific directories. This exploit leverages the way server paths and user home directories are handled, enabling privileged users to manipulate file accessibility in a manner that breaches the intended security model. The issue underscores the importance of strict directory management and the potential risks associated with admin privileges in file transfer applications on Windows systems.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Serv-U Windows SolarWinds Serv-U 15.5.2 and prior versions
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved