Attacks against SolarWinds Serv-U SW were possible due to the lack of ASLR mitigation

This article has been indexed from Security Affairs

SolarWinds did not enable anti-exploit mitigation available since 2006 allowing threat actors to target SolarWinds Serv-U FTP software in July attacks. Software vendor SolarWinds did not enable ASLR anti-exploit mitigation that was available since the launch of Windows Vista in 2006, allowing the attackers to launch targeted attacks in July. Microsoft, which investigated the incidents, […]

The post Attacks against SolarWinds Serv-U SW were possible due to the lack of ASLR mitigation appeared first on Security Affairs.

Read the original article: Attacks against SolarWinds Serv-U SW were possible due to the lack of ASLR mitigation