PT-2026-21671 · Serv-U · Serv-U
Published
2026-02-24
·
Updated
2026-03-10
·
CVE-2025-40541
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Serv-U versions 15.5.3 and earlier
Description
An Insecure Direct Object Reference (IDOR) vulnerability exists in Serv-U. Exploitation of this issue allows a malicious actor to execute native code as a privileged account. This requires administrative privileges to abuse. On Windows deployments, the risk is considered medium because services often run under less-privileged service accounts. The vulnerability allows an attacker to access or manipulate objects directly by manipulating parameters or identifiers without proper authorization checks.
Recommendations
Serv-U versions 15.5.3 and earlier should be updated to version 15.5.4 or later.
Fix
RCE
IDOR
Incorrect Type Conversion or Cast
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Serv-U