SolarWinds Serv-U Critical RCE Bug CVE-2024-28925 Lets Attackers Gain Root Access
Key Takeaways SolarWinds has released Serv-U version 15.5.4 to patch four critical vulnerabilities. These flaws, rated 9.1 CVSS each, could allow attackers to achieve root-level remote code...
Key Takeaways
- SolarWinds has released Serv-U version 15.5.4 to patch four critical vulnerabilities.
- These flaws, rated 9.1 CVSS each, could allow attackers to achieve root-level remote code execution.
- Affected systems include unpatched versions of the Serv-U file server software.
- A fix is available in Serv-U version 15.5.4, and immediate updates are strongly recommended.
A critical security update is urgently required for SolarWinds Serv-U file server software, as multiple severe vulnerabilities have been identified that could lead to complete system compromise if left unaddressed. The latest release, Serv-U version 15.5.4, specifically targets and remediates four high-severity security flaws, each carrying a CVSS score of 9.1.
Table Of Content
These vulnerabilities are particularly dangerous due to their potential for remote code execution (RCE), which would grant attackers the highest level of administrative control over affected infrastructure. Cybersecurity teams and system administrators are advised to review the official release notes and apply the necessary updates without delay to mitigate the risk of exploitation.
Serv-U Vulnerabilities Allow Root Access
The recently disclosed security issues fundamentally impact the core operations of the Serv-U application, allowing for the execution of arbitrary native code with root privileges. Among the most critical is a broken access control vulnerability, identified as CVE-2025-40538. This flaw enables attackers who possess domain or group administrator credentials to create a new system administrator user account. Once this unauthorized account is established, the adversary can execute malicious commands with full root privileges.
The software also suffers from two distinct type confusion vulnerabilities, CVE-2025-40539 and CVE-2025-40540. These memory corruption flaws in the Serv-U web interface offer a direct pathway for an attacker to run unauthorized native code as root. Furthermore, the update addresses an Insecure Direct Object Reference (IDOR) vulnerability, CVE-2025-40541, found in the Serv-U API and object handling. This specific flaw allows attackers to bypass authorization mechanisms by directly accessing internal objects, leading to remote code execution with root privileges.
The comprehensive control offered by these vulnerabilities means threat actors could leverage them for various malicious activities, including deploying ransomware, exfiltrating sensitive enterprise data, or establishing persistent backdoors within corporate networks. SolarWinds has publicly acknowledged and credited security researchers for their responsible disclosure of these issues and for collaborating with their engineering teams to develop effective patches.
Product Enhancements and Update Recommendations
Beyond the critical security patches, Serv-U version 15.5.4 introduces several functional improvements and expanded platform support. The application now officially supports Ubuntu 24.04 LTS, enhancing its deployment flexibility within enterprise environments. SolarWinds has also restored the download history feature in File Share, bringing it in line with capabilities found in the legacy web client. Additionally, the file share interface now displays a precise time alongside the last modified date.
To further bolster the application’s resilience against modern web threats, SolarWinds has implemented strict content security policy (CSP) configurations. The legacy login page, for instance, now uses specific directives designed to prevent the application from being maliciously embedded in other websites, thereby neutralizing potential clickjacking attacks. Administrators utilizing older versions of Serv-U should consult the end-of-life schedule, as earlier iterations, such as 15.5.1, reached the end of engineering support by February 18, 2026. Organizations are urged to download the latest installation files from the customer portal to ensure their infrastructure remains secure against these critical remote code execution threats.
What You Should Do
- Immediately update all Serv-U installations to version 15.5.4.
- Review the official SolarWinds Serv-U 15.5.4 release notes for full details on the patched vulnerabilities and new features.
- Verify that your Serv-U instances are running supported versions to ensure continued access to security updates.
- Implement strict network segmentation and access controls to limit potential lateral movement in case of a breach.
- Regularly back up critical data and test recovery procedures.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.