Security News > 2021 > July > Microsoft Says SolarWinds Serv-U Zero-Day Exploited by Chinese Group
Microsoft said on Tuesday that a recently patched SolarWinds Serv-U zero-day vulnerability has been exploited by a Chinese threat group.
IT management solutions provider SolarWinds over the weekend informed customers that its Serv-U Managed File Transfer and Serv-U Secure FTP products are affected by a remote code execution vulnerability that has been exploited in targeted attacks.
The vulnerability, tracked as CVE-2021-35211, affects Serv-U version 15.2.3 HF1 and earlier, and it has been patched with the release of 15.2.3 HF2. According to Microsoft, the vulnerability has been exploited by a threat actor it tracks as DEV-0322 - DEV stands for "Development group" and is assigned by the tech giant to groups for which it is highly confident about their origin or identity.
Microsoft said the zero-day vulnerability is related to the SSH protocol implementation in Serv-U. "If Serv-U's SSH is exposed to the internet, successful exploitation would give attackers ability to remotely run arbitrary code with privileges, allowing them to perform actions like install and run malicious payloads, or view and change data," Microsoft explained.
Both Microsoft and SolarWinds have made available indicators of compromise for attacks involving exploitation of CVE-2021-35211.
When the supply chain attack was being investigated, it came to light that a threat group believed to be operating out of China had exploited a vulnerability in SolarWinds' Orion product as part of a campaign that targeted at least one US government organization.
News URL
Related news
- Microsoft October 2024 Patch Tuesday fixes 5 zero-days, 118 flaws (source)
- Microsoft patches two zero-days exploited in the wild (CVE-2024-43573, CVE-2024-43572) (source)
- Week in review: Microsoft fixes two exploited zero-days, SOC teams are losing trust in security tools (source)
- Microsoft: Chinese hackers use Quad7 botnet to steal credentials (source)
- Microsoft Warns of Chinese Botnet Exploiting Router Flaws for Credential Theft (source)
- Microsoft November 2024 Patch Tuesday fixes 4 zero-days, 91 flaws (source)
- Microsoft November 2024 Patch Tuesday fixes 4 zero-days, 89 flaws (source)
- Microsoft fixes actively exploited zero-days (CVE-2024-43451, CVE-2024-49039) (source)
- Microsoft patches Windows zero-day exploited in attacks on Ukraine (source)
- Chinese hackers exploit Fortinet VPN zero-day to steal credentials (source)
Related Vulnerability
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-07-14 | CVE-2021-35211 | Out-of-bounds Write vulnerability in Solarwinds Serv-U Microsoft discovered a remote code execution (RCE) vulnerability in the SolarWinds Serv-U product utilizing a Remote Memory Escape Vulnerability. | 10.0 |