Tools

Serv-U: Potential elevation of privileges on Linux systems

This article details a reported privilege escalation vulnerability with Serv-U 15.1.6 and earlier.

First published date

6/5/2019 1:58 PM

Last published date

6/5/2019 1:58 PM

Overview

An external analyst reported a privilege escalation vulnerability with Serv-U 15.1.6 and earlier, specifically with installation of the Serv-U service on a Linux deployment. This issue was logged as CVE-2019-12181.

Product section

Serv-U Managed File Transfer & Serv-U FTP Server

Cause

Low privileged users could manipulate the installer arguments.

Resolution

SolarWinds encourages all customers to upgrade to Serv-U 15.1.7 or newer as soon as possible.