Vulnerability record · CVE-2018-19999 · published 7 June 2019
CVE-2018-19999: Solarwinds serv-u ftp server improper authentication vulnerability
Solarwinds · Serv U Ftp Server
The local management interface in SolarWinds Serv-U FTP Server 15.1.6.25 has incorrect access controls that permit local users to bypass authentication in the application and execute code in the context of the Windows SYSTEM account, leading to privilege escalation. To exploit this vulnerability, an attacker must have local access the the host running Serv-U, and a Serv-U administrator have an active management console session.
Description
The local management interface in SolarWinds Serv-U FTP Server 15.1.6.25 has incorrect access controls that permit local users to bypass authentication in the application and execute code in the context of the Windows SYSTEM account, leading to privilege escalation. To exploit this vulnerability, an attacker must have local access the the host running Serv-U, and a Serv-U administrator have an active management console session.
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://seclists.org/fulldisclosure/2019/May/46 | Mailing ListThird Party Advisory |
| https://www.themissinglink.com.au/security-advisories-cve-2018-19999 | Broken Link |
| https://seclists.org/fulldisclosure/2019/May/46 | Mailing ListThird Party Advisory |
| https://www.themissinglink.com.au/security-advisories-cve-2018-19999 | Broken Link |
Track CVE-2018-19999 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-19999), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.