Threat Actors Exploiting Log4j vulnerabilities propagated via SolarWinds Serv-U software

The cybersecurity researchers at Microsoft have recently identified a security flaw in SolarWinds Serv-U software that is exploited by the hackers to execute Log4j attacks to compromise the network of their victims.

While monitoring attacks using Log4j, the Microsoft expert, Jonathan Bar discovered this vulnerability which is tracked as “CVE-2021-35247.” However, SolarWinds has already fixed this vulnerability in Serv-U software in 15.3.

Flaw profile

  • Advisory ID: CVE-2021-35247
  • Description: Improper Input Validation Vulnerability in Serv-U.
  • First Published: 01/18/2022
  • Last Updated: 01/18/2022
  • Fixed Version: Serv-U 15.3
  • CVSS Score: CVSS:3.0/AV:N/AC:L/PR:N/UI:R
  • /S:C/C:N/I:L/A:N

This vulnerability is an input validation bug that enables a hacker to create a query and send the query over the network in an unverified form.

The Serv-U web login for LDAP authentication allows the attackers to use the characters that were not properly sanitized. While SolarWinds has already updated the input engine, adding an additional input validation and sanitization routine.

The LDAP servers ignore the invalid characters, which doesn’t come under the further development of the attack could occur. 

And that’s why it is not yet clear whether the threat actors tried to exploit the vulnerability and failed, or whether the attacks successfully continued by exploiting problems in Log4j.

But, since the LDAP servers ignored improper characters, so, till now there is no downstream effect has been detected yet.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity updates

Gurubaran

Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Recent Posts

INTERPOL Urges to End ‘Pig Butchering’ & Replaces With “Romance Baiting”

INTERPOL has called for the term "romance baiting" to replace "pig butchering," a phrase widely…

25 minutes ago

New I2PRAT Malware Using encrypted peer-to-peer communication to Evade Detections

Cybersecurity experts are sounding the alarm over a new strain of malware dubbed "I2PRAT," which…

1 hour ago

Earth Koshchei Employs RDP Relay, Rogue RDP server in Server Attacks

 A new cyber campaign by the advanced persistent threat (APT) group Earth Koshchei has brought…

3 hours ago

Careto – A legendary Threat Group Targets Windows By Deploy Microphone Recorder And Steal Files

Recent research has linked a series of cyberattacks to The Mask group, as one notable…

3 hours ago

RiseLoader Attack Windows By Employed A VMProtect To Drop Multiple Malware Families

RiseLoader, a new malware family discovered in October 2024, leverages a custom TCP-based binary protocol…

3 hours ago

1-Click RCE Attack In Kerio Control UTM Allow Attackers Gain Firewall Root Access Remotely

GFI Software's Kerio Control, a popular UTM solution, was found to be vulnerable to multiple…

3 hours ago