SolarWinds released a “hotfix” to resolve a critical remote code execution (RCE) bug in its Serv-U products. Microsoft recently notified the software vendor about the vulnerability exploitation involving “a limited, targeted set of customers and a single threat actor.” SolarWinds urges their customers using Serv-U to immediately install the fix.

Hackers, which Microsoft says in high confidence are based in China and have been dubbed DEV-0322, exploited the zero-day CVE-2021-35211 vulnerability. Microsoft designates the unidentified threat actor as a “development group (DEV group)” and assigns a tracking number for each group.

Microsoft Threat Intelligence Center observed the group has been targeting “entities in the U.S. Defense Industrial Base Sector and software companies.”

Once exploited, the bug can provide privileged access to run arbitrary code. This allows a hacker to install programs; view, change, or delete data; or run programs on the affected system.

SolarWinds claims this new vulnerability is completely unrelated to the Sunburst supply-chain attack that unfolded last year. 

According to SolarWinds advisory, the current vulnerability exists in all versions of Serv-U, which is a multi-protocol file server enabling files transfer from other networked computers through various means, including the latest version 15.2.3 HF1 released on May 5. Both Serv-U Managed File Transfer Server and Serv-U Secure FTP are affected.

However, if the secure shell (SSH) protocol is not enabled for Serv-U installation, this vulnerability does not exist. The company also confirmed that other SolarWinds products and N-able (formerly SolarWinds MSP) are not affected.

An Unpatched SolarWinds Bug Might Cause Supply-Chain Attacks 

This Serv-U vulnerability comes as SolarWinds is still recovering from the Orion software supply chain attack discovered in December 2020. The company now suspects the hackers likely gained access to their environment as early as January 2019.

 After the attackers broke into SolarWinds, they inserted malware into the vendor’s Orion software update that was pushed to about 18,000 customers beginning in March 2019. This allowed them to remain in organizations’ environments for months without being detected. 

 Threat researchers estimated that this supply-chain attack compromised approximately 100 private corporations, along with nine federal agencies’ networks including Homeland Security, National Nuclear Security Administration, and the Department of Energy

 How the attackers gained access is still under investigation, but SolarWinds internal investigation has narrowed down the initial entry point to three possibilities, including two that relate to an unpatched vulnerability in one of the company’s third-party software, which might have exposed an entry point to the system, according to SolarWinds CEO Sudhakar Ramakrishna.

 In the Sev-U vulnerability advisory, SolarWinds explained how to determine if customers’ environment was compromised, and how to access the updates. Additional details will be published in the future.