9.1
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Description
A logic error vulnerability exists in Serv-U which when abused could give a malicious actor with access to admin privileges the ability to execute code.
This issue requires administrative privileges to abuse. On Windows deployments, the risk is scored as a medium because services frequently run under less-privileged service accounts by default.
This issue requires administrative privileges to abuse. On Windows deployments, the risk is scored as a medium because services frequently run under less-privileged service accounts by default.
AI Analysis
Logic error vulnerability in Serv-U allowing remote code execution with admin privileges
Basic Information
ID
CVE-2025-40547
Source
SolarWinds
Published
Nov 18, 2025 at 08:35
Affected Product
Vendor
SolarWinds
Product
Serv-U
Version
SolarWinds Serv-U 15.5.2 and prior versions
Affected Versions
SolarWinds Serv-U SolarWinds Serv-U 15.5.2 and prior versions
CWE Classification
AI Assessment
AI Score
9.1 / 10
AI Severity
Critical
Vendor
SolarWinds
Product
Serv-U
Version
15.5.2 and prior versions