PT-2021-16497 · Solarwinds · Solarwinds Serv-U

Martin Rakhmanov

·

Published

2021-02-03

·

Updated

2022-07-12

·

CVE-2021-25276

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions: SolarWinds Serv-U versions prior to 15.2.2 Hotfix 1
Description: The issue concerns a directory containing user profile files, including password hashes, which is world readable and writable. An unprivileged Windows user with access to the server's filesystem can exploit this by copying a valid profile file to the directory, potentially gaining access to read or replace arbitrary files with LocalSystem privileges.
Recommendations: For versions prior to 15.2.2 Hotfix 1, update to version 15.2.2 Hotfix 1 to resolve the issue. As a temporary workaround, consider restricting access to the directory containing user profile files to prevent unauthorized modifications.

Exploit

Fix

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-25276

Affected Products

Solarwinds Serv-U