PT-2021-16497 · Solarwinds · Solarwinds Serv-U
Martin Rakhmanov
·
Published
2021-02-03
·
Updated
2022-07-12
·
CVE-2021-25276
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
SolarWinds Serv-U versions prior to 15.2.2 Hotfix 1
Description:
The issue concerns a directory containing user profile files, including password hashes, which is world readable and writable. An unprivileged Windows user with access to the server's filesystem can exploit this by copying a valid profile file to the directory, potentially gaining access to read or replace arbitrary files with LocalSystem privileges.
Recommendations:
For versions prior to 15.2.2 Hotfix 1, update to version 15.2.2 Hotfix 1 to resolve the issue. As a temporary workaround, consider restricting access to the directory containing user profile files to prevent unauthorized modifications.
Exploit
Fix
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Solarwinds Serv-U