CVE-2021-35211

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
14/07/2021
Last modified:
12/03/2025

Description

Microsoft discovered a remote code execution (RCE) vulnerability in the SolarWinds Serv-U product utilizing a Remote Memory Escape Vulnerability. If exploited, a threat actor may be able to gain privileged access to the machine hosting Serv-U Only. SolarWinds Serv-U Managed File Transfer and Serv-U Secure FTP for Windows before 15.2.3 HF2 are affected by this vulnerability.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:solarwinds:serv-u:*:*:*:*:*:*:*:* 15.2.3 (excluding)
cpe:2.3:a:solarwinds:serv-u:15.2.3:-:*:*:*:*:*:*
cpe:2.3:a:solarwinds:serv-u:15.2.3:hotfix1:*:*:*:*:*:*