vendor:
Serv-U
by:
Guy Levin
8.8
CVSS
HIGH
Privilege Escalation
269
CWE
Product Name: Serv-U
Affected Version From: 15.1.2006
Affected Version To: Unknown
Patch Exists: YES
Related CWE: CVE-2019-12181
CPE: a:rhino-software:serv-u:15.1.6
Platforms Tested:
2019
CVE-2019-12181 Serv-U 15.1.6 Privilege Escalation
This exploit allows an attacker to escalate their privileges in Serv-U version 15.1.6. By providing specific arguments to the program, an attacker can execute arbitrary commands with root privileges.
Mitigation:
Upgrade to a patched version of Serv-U or apply the vendor-provided patch.