Vulnerability record · CVE-2019-12181 · published 17 June 2019
CVE-2019-12181: SolarWinds Serv-U Linux privilege escalation via OS command injection
Solarwinds · Serv U Ftp Server
SolarWinds Serv-U before 15.1.7 on Linux contains an OS command injection flaw (CWE-78) that allows privilege escalation. The vulnerability is network-reachable with low privileges required and no user interaction, and public exploit code exists, making it a practical target for attackers who already hold a foothold on the host.
Description
A privilege escalation vulnerability exists in SolarWinds Serv-U before 15.1.7 for Linux.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with network reachability, low privileges required, no user interaction, public exploit code and very high EPSS, though not in KEV and requiring an existing low-privileged foothold.
What it is
SolarWinds Serv-U before 15.1.7 on Linux contains an OS command injection flaw (CWE-78) that allows privilege escalation. The vulnerability is network-reachable with low privileges required and no user interaction, and public exploit code exists, making it a practical target for attackers who already hold a foothold on the host.
Impact
An attacker with low privileges can execute arbitrary OS commands and escalate to higher privileges on the affected Linux system, gaining full control of confidentiality, integrity and availability of the host.
Attack surface
Reached over the network (AV:N) with low privileges required (PR:L) and no user interaction (UI:N), per the CVSS vector. The description does not specify the exact interface or endpoint used, so the precise entry point cannot be confirmed from this record.
Exploitation
Not listed in CISA KEV, but EPSS is high (0.65981, 99.2nd percentile) and multiple references are tagged Exploit, indicating public exploit code is available. No ransomware group usage is documented.
What to do
- Upgrade SolarWinds Serv-U to 15.1.7 or later on Linux systems, per the vendor release notes.
- If immediate patching is not possible, restrict network access to the Serv-U service and limit which accounts can authenticate.
- Run the Serv-U service under a least-privileged dedicated account to reduce the impact of command execution.
- Monitor vendor advisories and apply any follow-up fixes for the Serv-U Linux privilege escalation issue.
Detection
- Audit Serv-U process trees for unexpected child processes or shell invocations (e.g., sh, bash, curl, wget) spawned by the service.
- Review Linux authentication and sudo logs for privilege changes or anomalous command execution tied to the Serv-U service account.
- Check installed Serv-U version against 15.1.7 and flag any Linux host still running an older build.
- Alert on outbound network connections originating from the Serv-U process that are not part of normal FTP/MFT traffic.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2019-12181 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-12181), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.