Permissions, Privileges, and Access Controls in Serv-U FTP Server - CVE-2019-12181
Published: August 19, 2019 / Updated: June 17, 2021
Vulnerability details
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to unspecified error. A remote authenticated attacker can escalate privileges on the system by manipulating the installer arguments.
The vulnerability affects Serv-U releases on Linux systems.
Affected software
How to mitigate CVE-2019-12181
Links to Public Exploits and PoC-codes
- Exploit #6058 - Serv-U FTP Server < 15.1.7 - Local Privilege Escalation (2) (June 17, 2021)
- Exploit #6069 - Serv-U FTP Server - prepareinstallation Privilege Escalation (Metasploit) (June 17, 2021)
- Exploit #6070 - Serv-U FTP Server < 15.1.7 - Local Privilege Escalation (1) (June 17, 2021)
- Exploit #2043 - CVE-2019-12181 (LPE Exploit For CVE-2019-12181 (Serv-U FTP 15.1.6)) (March 18, 2020)
- Exploit #1562 - Serv-U FTP Server prepareinstallation Privilege Escalation (March 18, 2020)
External References
- http://packetstormsecurity.com/files/153333/Serv-U-FTP-Server-15.1.6-Privilege-Escalation.html
- https://blog.vastart.dev/2019/06/cve-2019-12181-serv-u-exploit-writeup.html
- https://documentation.solarwinds.com/en/success_center/servu/Content/Release_Notes/Servu_15-1-7_release_notes.htm
- https://support.solarwinds.com/SuccessCenter/s/article/Serv-U-Potential-elevation-of-privileges-on-Linux-systems