SolarWinds patched a critical zero-day in Serv-U Managed File Transfer and Serv-U Secure FTP after active exploitation was discovered against a limited number of customers. The flaw, tracked as CVE-2021-35211, affects Serv-U deployments with SSH enabled and allows pre-authentication remote code execution when the SSH service is exposed to the internet. SolarWinds released Serv-U 15.2.3 HF2 and said the issue did not affect other SolarWinds or N-able products, including Orion, and was unrelated to the SUNBURST supply-chain compromise.
Microsoft said the attacks were limited and targeted, attributing them with high confidence to DEV-0322, a China-based threat group that targeted organizations including U.S. Defense Industrial Base entities and software companies. Microsoft’s analysis found the bug resided in Serv-U’s SSH implementation, where malformed SSH traffic could trigger use of uninitialized data as a function pointer during AES-CTR decryption; exploitation was aided by exception handling behavior and disabled ASLR in key modules, enabling reliable ROP chains. Post-exploitation activity included Serv-U.exe spawning mshta.exe, cmd.exe, and powershell.exe, writing command output to internet-accessible directories, and creating unauthorized global users, prompting both Microsoft and SolarWinds to publish detections, hunting guidance, and compromise indicators.

See which actors are running it and whether you're in range.
7 events from the most recent confirmed update back to the earliest known activity.
SolarWinds updated its advisory with compromise-assessment guidance, including checking DebugSocketlog.txt for access-violation exceptions, reviewing suspicious child processes from Serv-U.exe, and hunting for listed IPs, files, and URLs. The update also noted the issue was unrelated to the SUNBURST supply-chain attack.
SolarWinds released Serv-U version 15.2.3 HF2 to remediate CVE-2021-35211 after Microsoft reported the flaw. The hotfix was issued to address the actively exploited SSH-related remote code execution vulnerability.
In early July, Microsoft observed limited, targeted exploitation of CVE-2021-35211 against SolarWinds Serv-U. MSTIC later attributed the activity with high confidence to DEV-0322, a China-based threat group, including targeting of U.S. Defense Industrial Base entities and software companies.
SolarWinds stated that the bug was present in Serv-U 15.2.3 HF1, which had been released in May 2021. The company also said all Serv-U versions prior to 15.2.3 HF1 were affected.
Microsoft released a detailed analysis of the Serv-U SSH vulnerability, explaining that a malformed pre-auth SSH sequence could trigger use of uninitialized data as a function pointer during AES-CTR decryption. The report also described exploitability factors such as disabled ASLR in Serv-U.dll and RhinoNET.dll and said Microsoft had shared its findings and a fuzzer with SolarWinds through coordinated disclosure.
Microsoft publicly disclosed that it had discovered the Serv-U zero-day exploitation campaign, attributed it to DEV-0322, and released detections, alerts, hunting guidance, and indicators of compromise. The guidance described observed post-exploitation behavior such as Serv-U spawning mshta.exe, cmd.exe, and PowerShell, and attackers creating crafted global user archive files for administrative access.
SolarWinds warned customers that CVE-2021-35211, a remote code execution flaw affecting Serv-U Managed File Transfer and Serv-U Secure FTP when SSH is enabled, was being actively exploited in the wild by a single threat actor against a limited number of customers. The company urged immediate patching and said other SolarWinds and N-able products were not affected.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
6 references tracked. Mallory keeps watching after this page renders.
microsoft.com
Open sourcemicrosoft.com
Open sourcebleepingcomputer.com
Open sourcesolarwinds.com
Open sourcedatatracker.ietf.org
Open sourcedatatracker.ietf.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.