SolarWinds Issues Hotfix for Zero-Day Flaw Under Active Attack
#1
Information 
Quote:SolarWinds has issued a hotfix for a zero-day remote code execution (RCE) vulnerability already under active, yet limited, attack on some of the company’s customers.
 
Microsoft alerted the company about the flaw, which affects its Serv-U Managed File Transfer Server and Serv-U Secured FTP products. Specifically, the vulnerability exists in the latest Serv-U version 15.2.3 HF1 released on May 5 of this year, as well as all prior versions, the company said in a security advisory posted over the weekend.
 
Microsoft provided a proof-of-concept (PoC) exploit to SolarWinds, demonstrating how a threat actor who successfully exploits the vulnerability could run arbitrary code with privileges, according to the advisory.
“An attacker could then install programs; view, change or delete data; or run programs on the affected system,” the computing giant said.
 
Though the current threat appears to be from a sole actor and “involves a limited, targeted set of customers,” SolarWinds wanted to remedy the situation before it could escalate, the company said. “Our joint teams have mobilized to address it quickly,” according to the advisory.
 
SolarWinds does not currently know many customers may be directly affected by the flaw, nor has it identified the ones who were targeted. The company is recommending that all customers using the affected products update now, which can be done by accessing the company’s customer portal.

Read more: SolarWinds Issues Hotfix for Zero-Day Flaw Under Active Attack | Threatpost
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Messages In This Thread
SolarWinds Issues Hotfix for Zero-Day Flaw Under Active Attack - by silversurfer - 14 July 21, 11:41

Forum Jump:


Users browsing this thread:
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Internet Download Manager 6.32 Build 9
Internet Download ...Kool — 05:17
AntGROUP Inc. / VCap-developer
Ant Download Manager...jasonX — 01:54
Windows 11 Build 26300.8493 Brings Movab...
Microsoft has rele...harlan4096 — 16:55
Google Chrome 148.0.7778.167/168
The security updat...harlan4096 — 07:15
Microsoft Edge 148.0.3967.70
Version 148.0.3967...harlan4096 — 07:12

[-]
Birthdays
Today's Birthdays
avatar (49)contjrat
Upcoming Birthdays
avatar (28)akiratoriyama
avatar (48)Jerrycix
avatar (40)awedoli
avatar (82)WinRARHowTo
avatar (39)axuben
avatar (40)ihijudu
avatar (50)Mirzojap
avatar (36)idilysaju
avatar (40)GregoryRog
avatar (40)odukoromu
avatar (46)Joanna4589

[-]
Online Staff
There are no staff members currently online.

>