Tools

Mitigating Serv-U vulnerability with 15.2.2 HF1 or manual intervention

Serv-U version 15.2.2 and older has a vulnerability (CVE-2021-25276) on Serv-U instances running under non-Admin accounts, which needs to be addressed either by installing 15.2.2 HF1 or by making a manual change of folder permissions. This article describes how to make these updates manually.

First published date

3/8/2021 8:56 PM

Last published date

12/3/2021 8:48 PM

Overview

When Serv-U is configured to run under a non-Admin account, the Serv-U instance may seem to disappear, or other issues may affect Serv-U. This vulnerability is normally solved applying 15.2.2 HF1, but can also be fixed by an administrator by updating the permission settings in the Serv-U folder manually instead.

 

Product section

Serv-U Managed File Transfer & Serv-U FTP Server

Cause

This may happen because insufficient rights and privileges mean a non-admin Serv-U service user (eg an account of local Windows or a Windows Domain) cannot modify the Access Control entries applied to the Serv-U program data.

Resolution

  1. Stop Serv-U.
  2. Add the Serv-U service account to the directory where the Serv-U data directories and files reside, providing the service account Full Control permission.
  3. For regular non-administrative users and user groups, remove any permisions from the Access Control List of the directory where the Serv-U data directories and files reside:
    1. Open the Serv-U Folder Properties and select the Security tab. ​​​​​​

      servu-1.png

    2. Click Advanced, and disable inheritance by clicking “Converting inherited permission into explicit permissions on this object.” servu-2.png
    3. Open Edit under the Group or user names box:

      servu-3.png

    4. Remove the allowing entries for Users and Groups which are NOT shown in the following list:
      • Administrators
      • Local System (often displayed as SYSTEM)
      • Backup Managers
      • The Serv-U account added per step 3.
  4. Make sure that all subfolders in Serv-U data directories have enabled the inheritance of the security attributes. See these examples:
  • File Serv-U.Archive
  • File Serv-UID.txt
  • Directory Users
  • Directory Shares
  1. Ensure only the required permissions are present in Serv-U directories and files.