CVE Feed

    Dashboard / CVE / CVE-2018-19999

    CVE-2018-19999

    The local management interface in SolarWinds Serv-U FTP Server 15.1.6.25 has incorrect access controls that permit local users to bypass authentication in the application and execute code in the context of the Windows SYSTEM account, leading to privilege escalation. To exploit this vulnerability, an attacker must have local access the the host running Serv-U, and a Serv-U administrator have an active management console session.

    Published:Jun 7, 2019
    Last Modified:Nov 21, 2024
    EPS:Jun 7, 2019
    EPSS Score:0.00056
    CVSS Score:7.8

    Affected Products

    Vendor
    Solarwinds
    Product
    Serv-u Ftp Server

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High