← Vulnerability feed

Vulnerability record · CVE-2019-12181 · published 17 June 2019

CVE-2019-12181: SolarWinds Serv-U Linux privilege escalation via OS command injection

Solarwinds · Serv U Ftp Server

SolarWinds Serv-U before 15.1.7 on Linux contains an OS command injection flaw (CWE-78) that allows privilege escalation. The vulnerability is network-reachable with low privileges required and no user interaction, and public exploit code exists, making it a practical target for attackers who already hold a foothold on the host.

8.8 CVSS 3.1 High EPSS 66% · top 0.7% CWE-78 · OS command injection
8.8CVSS 3.1 base score, v2 6.5
66%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
10References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

A privilege escalation vulnerability exists in SolarWinds Serv-U before 15.1.7 for Linux.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityCVSS 8.8 with network reachability, low privileges required, no user interaction, public exploit code and very high EPSS, though not in KEV and requiring an existing low-privileged foothold.

What it is

SolarWinds Serv-U before 15.1.7 on Linux contains an OS command injection flaw (CWE-78) that allows privilege escalation. The vulnerability is network-reachable with low privileges required and no user interaction, and public exploit code exists, making it a practical target for attackers who already hold a foothold on the host.

Impact

An attacker with low privileges can execute arbitrary OS commands and escalate to higher privileges on the affected Linux system, gaining full control of confidentiality, integrity and availability of the host.

Attack surface

Reached over the network (AV:N) with low privileges required (PR:L) and no user interaction (UI:N), per the CVSS vector. The description does not specify the exact interface or endpoint used, so the precise entry point cannot be confirmed from this record.

Exploitation

Not listed in CISA KEV, but EPSS is high (0.65981, 99.2nd percentile) and multiple references are tagged Exploit, indicating public exploit code is available. No ransomware group usage is documented.

What to do

  • Upgrade SolarWinds Serv-U to 15.1.7 or later on Linux systems, per the vendor release notes.
  • If immediate patching is not possible, restrict network access to the Serv-U service and limit which accounts can authenticate.
  • Run the Serv-U service under a least-privileged dedicated account to reduce the impact of command execution.
  • Monitor vendor advisories and apply any follow-up fixes for the Serv-U Linux privilege escalation issue.

Detection

  • Audit Serv-U process trees for unexpected child processes or shell invocations (e.g., sh, bash, curl, wget) spawned by the service.
  • Review Linux authentication and sudo logs for privilege changes or anomalous command execution tied to the Serv-U service account.
  • Check installed Serv-U version against 15.1.7 and flag any Linux host still running an older build.
  • Alert on outbound network connections originating from the Serv-U process that are not part of normal FTP/MFT traffic.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-12181 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-15541Solarwinds serv-u ftp server vulnerabilitySolarWinds Serv-U FTP server before 15.2.1 allows remote command execution.EPSS 7.0%9.8CVE-2020-15542Solarwinds serv-u ftp server vulnerabilitySolarWinds Serv-U FTP server before 15.2.1 mishandles the CHMOD command.EPSS 1.6%9.8CVE-2020-15543Solarwinds serv-u ftp server improper input validation vulnerabilitySolarWinds Serv-U FTP server before 15.2.1 does not validate an argument path.EPSS 1.6%7.8CVE-2018-19999Solarwinds serv-u ftp server improper authentication vulnerabilityThe local management interface in SolarWinds Serv-U FTP Server 15.1.6.25 has incorrect access controls that permit local users to bypass authenticati…EPSS 0.61%7.2CVE-2018-15906Solarwinds serv-u ftp server vulnerabilitySolarWinds Serv-U FTP Server 15.1.6 allows remote authenticated users to execute arbitrary code by leveraging the Import feature and modifying a CSV …EPSS 8.1%6.5CVE-2019-13181Solarwinds serv-u ftp server csv injection vulnerabilityA CSV injection vulnerability exists in the web UI of SolarWinds Serv-U FTP Server v15.1.7.EPSS 3.2%5.4CVE-2019-19829Solarwinds serv-u ftp server cross-site scripting vulnerabilityA cross-site scripting (XSS) vulnerability exists in SolarWinds Serv-U FTP Server 15.1.7 in the email parameter, a different vulnerability than CVE-2…EPSS 2.3%5.4CVE-2019-13182Solarwinds serv-u ftp server cross-site scripting vulnerabilityA stored cross-site scripting (XSS) vulnerability exists in the web UI of SolarWinds Serv-U FTP Server 15.1.7.EPSS 6.4%

Source: NIST National Vulnerability Database (record CVE-2019-12181), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.