支持本站 — 捐款将帮助我们持续运营

目标:1000 元,已筹:752

75.2%
一、 漏洞 CVE-2025-40547 基础信息
漏洞信息
                                        # Serv-U 逻辑滥用远程代码执行漏洞

## 概述

Serv-U 中存在一个逻辑错误漏洞,攻击者若具备管理员权限,可利用该漏洞执行任意代码。

## 影响版本

未明确具体版本,但漏洞存在于 Serv-U 产品中。

## 细节

该漏洞是由于 Serv-U 的逻辑处理不当,在具有管理员访问权限的条件下可以被滥用,从而实现代码执行。

## 影响

漏洞利用需要管理员权限。在 Windows 部署环境中,由于服务通常默认以低权限服务账户运行,因此风险评级为中等。
                                        
神龙判断

是否为 Web 类漏洞: 未知

判断理由:

N/A
提示
尽管我们采用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。
神龙会尽力确保数据准确,但也请结合实际情况进行甄别与判断。
神龙祝您一切顺利!
漏洞标题
SolarWinds Serv-U Logic Abuse - Remote Code Execution Vulnerability
来源:美国国家漏洞数据库 NVD
漏洞描述信息
A logic error vulnerability exists in Serv-U which when abused could give a malicious actor with access to admin privileges the ability to execute code. This issue requires administrative privileges to abuse. On Windows deployments, the risk is scored as a medium because services frequently run under less-privileged service accounts by default.
来源:美国国家漏洞数据库 NVD
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
来源:美国国家漏洞数据库 NVD
漏洞类别
对输出编码和转义不恰当
来源:美国国家漏洞数据库 NVD
漏洞标题
SolarWinds Serv-U 安全漏洞
来源:中国国家信息安全漏洞库 CNNVD
漏洞描述信息
SolarWinds Serv-U是美国SolarWinds公司的一款 FTP(文件传输协议)服务器软件。 SolarWinds Serv-U存在安全漏洞,该漏洞源于逻辑错误,可能导致管理员权限的攻击者执行代码。
来源:中国国家信息安全漏洞库 CNNVD
CVSS信息
N/A
来源:中国国家信息安全漏洞库 CNNVD
漏洞类别
其他
来源:中国国家信息安全漏洞库 CNNVD
二、漏洞 CVE-2025-40547 的公开POC
#POC 描述源链接神龙链接
1CVE-2025-40547https://github.com/B1ack4sh/Blackash-CVE-2025-40547POC详情
2Nonehttps://github.com/zigzagymym1986/CVE-2025-40547POC详情
3CVE-2025-40547https://github.com/Ashwesker/Blackash-CVE-2025-40547POC详情
4CVE-2025-40547https://github.com/Ashwesker/Ashwesker-CVE-2025-40547POC详情
三、漏洞 CVE-2025-40547 的情报信息
  • https://www.solarwinds.com/trust-center/security-advisories/CVE-2025-40547
  • 标题: Serv-U 15.5.3 release notes -- 🔗来源链接

    标签:

    神龙速读:
                                            ### 关键漏洞信息
    
    #### SolarWinds CVEs
    
    | CVE-ID    | Vulnerability Title               | Description                                                                                                                                                                                                                      | Severity | Credit     |
    |-----------|--------------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|----------|------------|
    | CVE-2025-40547 | Logic Abuse - Remote Code Execution Vulnerability | A logic error vulnerability exists in Serv-U, which when abused, could give a malicious actor with access to admin privileges the ability to execute code. This issue requires administrative privileges to abuse. | Critical | 9.1        |
    | CVE-2025-40548 | Broken Access Control - Remote Code Execution Vulnerability | A missing validation process exists in Serv-U, which when abused, could give a malicious actor with access to admin privileges the ability to execute code. This issue requires administrative privileges to abuse. | Critical | 9.1        |
    | CVE-2025-40549 | Path Restriction Bypass Vulnerability                       | A Path Restriction Bypass vulnerability exists in Serv-U that when abused, could give a malicious actor with access to admin privileges the ability to execute code on a directory. This issue requires administrative privileges to abuse. | Critical | 9.1        |
    
    #### 解决的客户问题
    
    | Case number | Description                                                                                                                                                                                                                                                                                          |
    |-------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
    | N/A         | An error alert again displays after multi-factor authentication (MFA) when Web Client and File Sharing are disabled for the user.                                                                                                                                                                         |
    | N/A         | Serv-U no longer ignores listeners created to accept client connections.                                                                                                                                                                                                                               |
    | N/A         | Case-insensitive counting for ASCII usernames was implemented to prevent brute force attempts that exceed limits.                                                                                                                                                                                              |
    | N/A         | Serv-U now prevents attacks by blocking the processing of specially crafted URLs designed to create XSS vulnerabilities.                                                                                                                                                                                     |
    | N/A         | 'Unsafe-inline' was removed from the style-src directive, and nonce was applied to style elements. Inline styles were refactored to CSS classes, and the cdk-virtual-scroll-viewport component was replaced with standard Nova-UI table implementations for better Content Security Policy (CSP) compliance. |
    | 01985676    | Serv-U suggests available space identified for \\OneHost\DirectoryForHome.                                                                                                                                                                                                                             |
    | 01984223    | Serv-U continues to operate as expected when it allows LDAP users.                                                                                                                                                                                                                                     |
                                            
    Serv-U 15.5.3 release notes
  • https://nvd.nist.gov/vuln/detail/CVE-2025-40547
四、漏洞 CVE-2025-40547 的评论
匿名用户
2026-01-15 06:09:32

Zaproxy alias impedit expedita quisquam pariatur exercitationem. Nemo rerum eveniet dolores rem quia dignissimos.


发表评论