Tools
Mitigating Serv-U vulnerability with 15.2.2 HF1 or manual intervention
Serv-U version 15.2.2 and older has a vulnerability (CVE-2021-25276) on Serv-U instances running under non-Admin accounts, which needs to be addressed either by installing 15.2.2 HF1 or by making a manual change of folder permissions. This article describes how to make these updates manually.
First published date
Last published date
Overview
Product section
Cause
Resolution
- Stop Serv-U.
- Add the Serv-U service account to the directory where the Serv-U data directories and files reside, providing the service account Full Control permission.
- For regular non-administrative users and user groups, remove any permisions from the Access Control List of the directory where the Serv-U data directories and files reside:
- Open the Serv-U Folder Properties and select the Security tab.
- Click Advanced, and disable inheritance by clicking “Converting inherited permission into explicit permissions on this object.”
- Open Edit under the Group or user names box:
- Remove the allowing entries for Users and Groups which are NOT shown in the following list:
- Administrators
- Local System (often displayed as SYSTEM)
- Backup Managers
- The Serv-U account added per step 3.
- Open the Serv-U Folder Properties and select the Security tab.
- Make sure that all subfolders in Serv-U data directories have enabled the inheritance of the security attributes. See these examples:
- File Serv-U.Archive
- File Serv-UID.txt
- Directory Users
- Directory Shares
- Ensure only the required permissions are present in Serv-U directories and files.