CVE-2021-35211

CRITICAL KEV RANSOMWARE NUCLEI

SolarWinds Serv-U <15.2.3 HF2 - RCE

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2021-35211 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added November 3, 2021, with confirmed use in ransomware campaigns. EIP tracks 4 public exploits from researchers including NattiSamson, 0xhaggis. A Nuclei detection template is also available.

AI-analyzed exploit summary This PoC exploits a heap-based buffer overflow in SolarWinds Serv-U SSH server (CVE-2021-35211) by spraying crafted SSH packets to corrupt memory and trigger arbitrary code execution. The exploit leverages ROP techniques and targets the SSH key exchange process.

Description

Microsoft discovered a remote code execution (RCE) vulnerability in the SolarWinds Serv-U product utilizing a Remote Memory Escape Vulnerability. If exploited, a threat actor may be able to gain privileged access to the machine hosting Serv-U Only. SolarWinds Serv-U Managed File Transfer and Serv-U Secure FTP for Windows before 15.2.3 HF2 are affected by this vulnerability.

Exploits (4)

nomisec WORKING POC 12 stars
by NattiSamson · remote
https://github.com/NattiSamson/Serv-U-CVE-2021-35211

This PoC exploits a heap-based buffer overflow in SolarWinds Serv-U SSH server (CVE-2021-35211) by spraying crafted SSH packets to corrupt memory and trigger arbitrary code execution. The exploit leverages ROP techniques and targets the SSH key exchange process.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: SolarWinds Serv-U SSH Server (versions before 15.2.5)
No auth needed
Prerequisites: Network access to vulnerable Serv-U SSH server · Serv-U version < 15.2.5
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WRITEUP 1 stars
by 0xhaggis · remote
https://github.com/0xhaggis/CVE-2021-35211

This repository contains a detailed technical walkthrough of developing a ROP-based exploit for CVE-2021-35211, a vulnerability in Serv-U FTP v15.2.3.717. It includes an analysis of the vulnerability, exploit development steps, and a Python-based PoC.

Classification
Writeup 100%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: Serv-U FTP v15.2.3.717
No auth needed
Prerequisites: Serv-U FTP v15.2.3.717 · Python 3 · Disassembler (e.g., Hopper, IDA Pro, Ghidra) · Radare2 · WinDBG
devstral-2 · analyzed Feb 18, 2026 Full analysis →
vulncheck_xdb WORKING POC
remote
https://github.com/BishopFox/CVE-2021-35211

This repository contains a functional exploit for CVE-2021-35211, a memory corruption vulnerability in Serv-U FTP for Windows, allowing remote code execution. The exploit includes ROP chains and multiple execution modes (command execution, shellcode stager, download/exec).

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Racy
Target: Serv-U FTP for Windows (versions 15.1.5.10, 15.2.3.717, and other 15.x.y.z)
No auth needed
Prerequisites: Network access to the Serv-U FTP server (default port 22) · Target must be running a vulnerable version of Serv-U FTP
devstral-2 · analyzed Feb 25, 2026 Full analysis →
inthewild WORKING POC
poc
https://github.com/bishopfox/cve-2021-35211

This repository contains a functional exploit for CVE-2021-35211, a memory corruption vulnerability in Serv-U FTP for Windows, allowing remote code execution. The exploit includes ROP chains and multiple execution modes (command execution, shellcode stager, download/exec).

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Racy
Target: Serv-U FTP Server 15.2.3.717
No auth needed
Prerequisites: Network access to Serv-U FTP server · Target running vulnerable Serv-U version
devstral-2 · analyzed Feb 23, 2026 Full analysis →

Nuclei Templates (1)

SolarWinds Serv-U FTP - Remote Code Execution
CRITICALVERIFIEDby pussycat0x
Shodan: SSH-2.0-Serv-U

Scores

CVSS v3 9.0
EPSS 0.9432
EPSS Percentile 100.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact total

Details

CISA KEV 2021-11-03
VulnCheck KEV 2021-07-13
InTheWild.io 2021-07-13
ENISA EUVD EUVD-2021-21854
Ransomware Use Confirmed
CWE
CWE-787
Status published
Products (2)
solarwinds/serv-u 15.2.3 (2 CPE variants)
solarwinds/serv-u < 15.2.3
Published Jul 14, 2021
KEV Added Nov 03, 2021
Tracked Since Feb 18, 2026