Security News > 2021 > July > Microsoft Says SolarWinds Serv-U Zero-Day Exploited by Chinese Group

Microsoft Says SolarWinds Serv-U Zero-Day Exploited by Chinese Group
2021-07-14 10:03

Microsoft said on Tuesday that a recently patched SolarWinds Serv-U zero-day vulnerability has been exploited by a Chinese threat group.

IT management solutions provider SolarWinds over the weekend informed customers that its Serv-U Managed File Transfer and Serv-U Secure FTP products are affected by a remote code execution vulnerability that has been exploited in targeted attacks.

The vulnerability, tracked as CVE-2021-35211, affects Serv-U version 15.2.3 HF1 and earlier, and it has been patched with the release of 15.2.3 HF2. According to Microsoft, the vulnerability has been exploited by a threat actor it tracks as DEV-0322 - DEV stands for "Development group" and is assigned by the tech giant to groups for which it is highly confident about their origin or identity.

Microsoft said the zero-day vulnerability is related to the SSH protocol implementation in Serv-U. "If Serv-U's SSH is exposed to the internet, successful exploitation would give attackers ability to remotely run arbitrary code with privileges, allowing them to perform actions like install and run malicious payloads, or view and change data," Microsoft explained.

Both Microsoft and SolarWinds have made available indicators of compromise for attacks involving exploitation of CVE-2021-35211.

When the supply chain attack was being investigated, it came to light that a threat group believed to be operating out of China had exploited a vulnerability in SolarWinds' Orion product as part of a campaign that targeted at least one US government organization.


News URL

http://feedproxy.google.com/~r/securityweek/~3/zE6lG5s0XXQ/microsoft-says-solarwinds-serv-u-zero-day-exploited-chinese-group

Related Vulnerability

DATE CVE VULNERABILITY TITLE RISK
2021-07-14 CVE-2021-35211 Out-of-bounds Write vulnerability in Solarwinds Serv-U
Microsoft discovered a remote code execution (RCE) vulnerability in the SolarWinds Serv-U product utilizing a Remote Memory Escape Vulnerability.
network
low complexity
solarwinds CWE-787
critical
10.0

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Microsoft 700 776 4531 4644 3617 13568
Solarwinds 56 33 101 81 50 265