#VU50292 Incorrect default permissions in Serv-U FTP Server - CVE-2021-25276
Published: February 3, 2021
Serv-U FTP Server
SolarWinds
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to incorrect default permissions on the Windows "Users" directory. A local user with access to the system can view contents of files and obtain users' password hashes from the "%ProgramData%\RhinoSoft\Serv-U\Users\<DOMAIN>\" directory.