PT-2025-47268 · Serv-U · Serv-U

Published

2025-11-18

·

Updated

2025-12-02

·

CVE-2025-40548

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Serv-U versions 15.5.2 and prior
Description A flaw exists in Serv-U due to a missing validation process. This can allow an attacker with administrative privileges to execute code on a vulnerable system. The risk is considered medium on Windows deployments because services often run under less-privileged service accounts. The vulnerability requires administrative privileges to exploit.
Recommendations Serv-U versions prior to 15.5.2 should be updated.

Fix

RCE

Improper Privilege Management

Weakness Enumeration

Related Identifiers

BDU:2025-14671
CVE-2025-40548

Affected Products

Serv-U