
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-40547 is a logic error vulnerability in SolarWinds Serv-U that allows an authenticated attacker with administrative privileges to execute arbitrary code. It affects SolarWinds Serv-U versions 15.5.2 and prior (specifically up to and including 15.5.2.2.102). The vulnerability was first published on November 18, 2025, with a patch released the same day in Serv-U 15.5.3. It carries a CVSS v3.1 base score of 9.1 (Critical), though SolarWinds notes that on Windows deployments the risk is scored as medium due to services typically running under less-privileged accounts (SolarWinds Advisory, Serv-U 15.5.3 Release Notes).
The root cause is classified as CWE-116 (Improper Encoding or Escaping of Output), manifesting as a logic error in Serv-U's processing that can be abused to achieve remote code execution. Exploitation requires an attacker to already possess administrative credentials to the Serv-U management interface, making this a post-authentication vulnerability. The attack vector is network-based with low attack complexity and no user interaction required, but the high privilege prerequisite significantly limits the attack surface. No public technical write-up or proof-of-concept code detailing the specific exploitation mechanics has been confirmed at this time (SolarWinds Advisory, Feedly).
Successful exploitation grants an authenticated administrator the ability to execute arbitrary code on the Serv-U host, resulting in full compromise of confidentiality, integrity, and availability. The CVSS scope is marked as "Changed," indicating that exploitation can impact resources beyond the Serv-U application itself, potentially enabling lateral movement within the network. On Linux deployments, where Serv-U may run under a highly privileged account, the impact is especially severe; on Windows, the risk is somewhat mitigated by services typically running under less-privileged service accounts (SolarWinds Advisory, Serv-U 15.5.3 Release Notes).
As of the time of disclosure, there is no confirmed public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Feedly). A GitHub repository named B1ack4sh/Blackash-CVE-2025-40547 appeared shortly after disclosure, though its content and reliability have not been independently verified. The EPSS score is approximately 0.092%, indicating a low probability of exploitation in the near term. CVE-2025-40547 has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
SolarWinds has released Serv-U version 15.5.3, which addresses CVE-2025-40547 along with two other critical CVEs (CVE-2025-40548 and CVE-2025-40549). Organizations should upgrade to Serv-U 15.5.3 immediately. As interim measures, administrators should restrict and audit administrative access to the Serv-U management interface, enforce strong authentication and the principle of least privilege for admin accounts, and monitor administrative activity and network traffic for anomalies (SolarWinds Advisory, Serv-U 15.5.3 Release Notes).
The vulnerability received coverage from multiple security news outlets including GBHackers, SecurityAffairs, CyberSecurityNews, and SecurityOnline, which highlighted the critical CVSS score and the broader context of three simultaneous critical CVEs patched in Serv-U 15.5.3. Community discussion appeared on Reddit (r/pwnhub) and Mastodon (infosec.exchange), with general consensus that the high privilege requirement reduces immediate risk but that patching remains urgent given SolarWinds' history as a high-value target. The Hacker News weekly recap also included mention of the Serv-U vulnerabilities in its November 2025 roundup (SecurityAffairs, SecurityOnline, The Hacker News).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."