← Back to CVE List
Vulnerability Intelligence Report
Serv-U Remote Memory Escape Vulnerability

CVE-2021-35211

Microsoft discovered a remote code execution (RCE) vulnerability in the SolarWinds Serv-U product utilizing a Remote Memory Escape Vulnerability. If exploited, a threat actor may be able to gain privileged access to the machine hosting Serv-U Only. SolarWinds Serv-U Managed File Transfer and Serv-U Secure FTP for Windows before 15.2.3 HF2 are affected by this vulnerability.

CISA KEV Nuclei Template SSVC: Active Exploitation
CVSS Base Score
9.0
CRITICAL
Exploitability:2.3
Impact Score:6.1
EPSS Probability:91.16%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-787 ↗CWE-787 Out-of-bounds Write

Affected Products & Versions

Vendor Product Affected Versions
SolarWinds Serv-U Managed File Transfer Server and Serv-U Secured FTP SolarWinds Serv-U < 15.2.3 HF1 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
Nuclei Template
SCANNER AVAILABLE
EPSS Score
91.160%

Identity & Timeline

StatusPUBLISHED
Assigning AuthoritySolarWinds · Vendor · USA
Reserved2021-06-22T00:00:00
Published2021-07-14T20:55:25
Patch Date2021-07-13
Last Updated2025-10-21T23:25:40

LINK COPIED TO CLIPBOARD