Attacks against SolarWinds Serv-U SW were possible due to the lack of ASLR mitigation
Security Affairs
SEPTEMBER 2, 2021
SolarWinds did not enable anti-exploit mitigation available since 2006 allowing threat actors to target SolarWinds Serv-U FTP software in July attacks. Software vendor SolarWinds did not enable ASLR anti-exploit mitigation that was available since the launch of Windows Vista in 2006, allowing the attackers to launch targeted attacks in July.
Let's personalize your content