Vulnerability record · CVE-2021-35211 · published 14 July 2021
CVE-2021-35211: SolarWinds Serv-U out-of-bounds write enables remote code execution
Solarwinds · Serv U
SolarWinds Serv-U Managed File Transfer and Serv-U Secure FTP for Windows before 15.2.3 HF2 contain an out-of-bounds write (CWE-787) that Microsoft described as a remote memory escape leading to remote code execution. The flaw was exploited as a zero-day before patches were available, and it is listed in CISA's Known Exploited Vulnerabilities catalog.
Description
Microsoft discovered a remote code execution (RCE) vulnerability in the SolarWinds Serv-U product utilizing a Remote Memory Escape Vulnerability. If exploited, a threat actor may be able to gain privileged access to the machine hosting Serv-U Only. SolarWinds Serv-U Managed File Transfer and Serv-U Secure FTP for Windows before 15.2.3 HF2 are affected by this vulnerability.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 10.0, unauthenticated network RCE, confirmed zero-day exploitation, KEV listing with ransomware use, and near-maximum EPSS make this an urgent patch-first issue.
What it is
SolarWinds Serv-U Managed File Transfer and Serv-U Secure FTP for Windows before 15.2.3 HF2 contain an out-of-bounds write (CWE-787) that Microsoft described as a remote memory escape leading to remote code execution. The flaw was exploited as a zero-day before patches were available, and it is listed in CISA's Known Exploited Vulnerabilities catalog.
Impact
An unauthenticated attacker can execute code with privileged access on the machine hosting Serv-U, giving full control of that host and any data or credentials it handles.
Attack surface
The CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates the flaw is reachable over the network with no authentication and no user interaction, so any exposed Serv-U service is directly attackable.
Exploitation
CISA added it to KEV on 2021-11-03 with a 2021-11-17 remediation due date and flags known ransomware campaign use; EPSS is 0.9116 (99.8th percentile), and references are tagged Patch and Vendor Advisory, confirming active exploitation and available fixes.
What to do
- Upgrade Serv-U Managed File Transfer and Serv-U Secure FTP for Windows to 15.2.3 HF2 or later.
- If immediate patching is not possible, restrict network access to the Serv-U service to trusted hosts only.
- Place Serv-U behind a firewall or VPN and avoid exposing it directly to the internet.
- Monitor vendor advisories for follow-up fixes and verify the installed build after upgrading.
- Review host logs for signs of compromise on any Serv-U server that was internet-exposed before patching.
Detection
- Hunt for unexpected child processes spawned by the Serv-U service, especially command shells or scripting interpreters.
- Monitor Serv-U logs and host telemetry for crashes, memory errors or abnormal service restarts.
- Alert on outbound connections from Serv-U hosts to unfamiliar external addresses.
- Correlate Serv-U host activity with known post-exploitation behavior such as credential access or lateral movement.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-35211 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "SolarWinds Serv-U Remote Code Execution Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 17 November 2021.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.microsoft.com/security/blog/2021/07/13/microsoft-discovers-threat-actor-targeting-solarwinds-serv-u-software | PatchVendor Advisory |
| https://www.solarwinds.com/trust-center/security-advisories/cve-2021-35211 | PatchVendor Advisory |
| https://www.microsoft.com/security/blog/2021/07/13/microsoft-discovers-threat-actor-targeting-solarwinds-serv-u-software | PatchVendor Advisory |
| https://www.solarwinds.com/trust-center/security-advisories/cve-2021-35211 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-35211 | US Government Resource |
Track CVE-2021-35211 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-35211), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.