Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
High

Type Confusion RCE in SolarWinds Serv-U

IdentifiersCVE-2025-40540CWE-704· Incorrect Type Conversion or Cast

CVE-2025-40540 is a type confusion vulnerability in SolarWinds Serv-U, including affected Serv-U 15.5 deployments. When successfully exploited, the flaw allows execution of arbitrary native code in a privileged context. Available reporting indicates the issue is associated with the Serv-U web interface/application logic and is classified as a type confusion weakness. SolarWinds states exploitation requires administrative privileges, meaning the attacker must already possess high-level authenticated access to the Serv-U environment before abusing the flaw. On Windows, the vendor notes risk may be somewhat reduced where the service runs under a less-privileged service account by default; however, the vulnerability can still result in privileged code execution depending on deployment context. The issue was fixed in Serv-U version 15.5.4.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation provides arbitrary native code execution as the privileged account under which Serv-U is running, which can amount to root/system-level compromise on affected deployments. This can enable full takeover of the Serv-U host, installation of persistent malware or backdoors, execution of attacker-controlled commands, access to sensitive files handled by the managed file transfer environment, and use of the server as a pivot point for lateral movement. Confidentiality, integrity, and availability impact are all high. On Windows, practical impact may be moderated if the service is running as a constrained service account rather than full administrative context.

Mitigation

If you can’t patch tonight, do this now.

If immediate patching is not possible, restrict Serv-U administrative access to trusted internal networks, dedicated management segments, or VPN-only paths; enforce MFA for administrative accounts; minimize the number of Serv-U administrators; monitor for suspicious admin activity and anomalous code execution from the Serv-U host; and ensure the Serv-U service runs with the least privileges possible, especially on Windows. Also review for prior credential exposure, password reuse, and signs of post-compromise abuse, since exploitation requires administrative access.

Remediation

Patch, then assume compromise.

Upgrade SolarWinds Serv-U to version 15.5.4, which remediates CVE-2025-40540. Validate that the update has been successfully applied across all Serv-U nodes/components and obtain installers directly from SolarWinds. If compromise is suspected, patching alone is insufficient: review Serv-U administrative activity, investigate for malicious code execution or persistence, and rotate relevant administrative credentials.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

EXPOSURE SURFACE

Affected products & vendors

Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.

VendorProductType
SolarWindsServ-Uapplication
SolarWindsServ-U Ftp-Serverapplication
SolarWindsServ-U Mftapplication

Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence

Every observed campaign linking this CVE to a named adversary.

Associated malware

Malware families riding this exploit, with evidence and IOCs.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity13

Community discussion across Reddit, Mastodon, and other social sources.