Back to CVE List

CVE-2025-40539

CRITICAL SEVERITY

CVSS Score & Metrics

Base Score
9.1 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Vulnerability Description

A type confusion vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to execute arbitrary native code as privileged account.

This issue requires administrative privileges to abuse. On Windows deployments, the risk is scored as a medium because services frequently run under less-privileged service accounts by default.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-704
Source
NVD
Vendor
SolarWinds
Product
Serv-U

External References

Discussion (0)

Add Comment

No comments yet. Be the first!