CVE-2018-19999
The local management interface in SolarWinds Serv-U FTP Server 15.1.6.25 has incorrect access controls that permit local users to bypass authentication in the application and execute code in the context of the Windows SYSTEM account, leading to…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.60%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The local management interface in SolarWinds Serv-U FTP Server 15.1.6.25 has incorrect access controls that permit local users to bypass authentication in the application and execute code in the context of the Windows SYSTEM account, leading to privilege escalation. To exploit this vulnerability, an attacker must have local access the the host running Serv-U, and a Serv-U administrator have an active management console session.
- CVSS 3.0
- 7.8 HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.60% probability · 47th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- solarwinds/serv-u ftp server
- Source
- cve@mitre.org
References
- https://seclists.org/fulldisclosure/2019/May/46Mailing List, Third Party Advisory
- https://www.themissinglink.com.au/security-advisories-cve-2018-19999Broken Link
- https://seclists.org/fulldisclosure/2019/May/46Mailing List, Third Party Advisory
- https://www.themissinglink.com.au/security-advisories-cve-2018-19999Broken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.