Tools

Execute Command Function Allows Remote Code Execution (RCE) Vulnerability (CVE-2021-35223)

This article describes an attack on Serv-U, where hackers can remotely run arbitrary code with privileges, and how administrators can prevent this exploitation.

First published date

8/23/2021 7:36 PM

Last published date

8/23/2021 7:36 PM

Overview

Administrators can configure the Serv-U server to allow domain users to execute programs on the host machine on which the server runs. Running a program on the server host is implemented as FTP command SITE EXEC.

When allowed, programs are executed under the same account as the Serv-U server. This means domain users can then run programs that access and change Serv-U information.

To prevent domain users from doing this, Serv-U can restrict programs from running if they are not explicitly or implicitly defined in Directory Access rules. However, Windows Batch Script programs can interpret special characters '<', '>', '&', and '|' (pipe) in the command line as instructions to "read", "execute", and "write" files and programs from/to locations which are not allowed by Directory Access rules. This can escalate privileges for a lower privileged user on the Serv-U server and enable malicious operations.

Product section

Serv-U Managed File Transfer & Serv-U FTP Server

Cause

CVE-2021-35223

Resolution

  1. Update Serv-U with the most recent version of Serv-U. Now Serv-U will "escape" the command-line characters '<', '>', '&', and '|' (pipe) - that is, it converts them to regular characters, which cannot "instruct" Windows Command shell to do anything.
  2. When creating a Directory Access Rule, avoid allowing the execution of programs that are explicitly or implicitly addressed by the rule if the programs are not thoroughly quality assured from the security perspective. Fortunately, the "execute" permission is set to OFF by default.
  3. To avoid accidentally running a dangerous or malicious program in a Directory Access Rule, DO block the FTP SITE EXEC command for Server or Domain(s). Such prevention is applicable only if there is no one case where a Domain User can run a program across the Server or Domain. To block the FTP SITE COMMAND:
    1. Open the Serv-U Management Console.
    2. Navigate to Server or Domain Limits & Settings and click the FTP Settings tab.
    3. In the case of Domain Limits & Settings, click the Use custom settings button.
    4. From the list of FTP commands, select SITE EXEC and click Edit. The FTP Command Properties dialog is displayed.
    5. Set Disable command to ON.