vendor:
Serv-U FTP Server
by:
bcoles
8.8
CVSS
HIGH
Local root exploit
264
CWE
Product Name: Serv-U FTP Server
Affected Version From: Prior to 15.1.7
Affected Version To: 15.1.7
Patch Exists: YES
Related CWE: CVE-2019-12181
CPE: a:solarwinds:serv-u_ftp_server
Other Scripts:
N/A
Platforms Tested: Linux
2019
SUroot – Local root exploit for Serv-U FTP Server versions prior to 15.1.7 (CVE-2019-12181)
SUroot is a local root exploit for Serv-U FTP Server versions prior to 15.1.7 (CVE-2019-12181). It is a Bash variant of Guy Levin's Serv-U FTP Server exploit. The exploit works by setting the /usr/local/Serv-U/Serv-U binary to setuid root and then executing a command to copy /bin/bash to /tmp/sh and set the ownership and permissions of the file to root. The exploit then launches a root shell using the /tmp/sh binary.
Mitigation:
Upgrade to Serv-U FTP Server version 15.1.7 or later.