Discovered by Chris Moberly on behalf of The Missing Link Security
SolarWinds Serv-U FTP Server is vulnerable to privilege escalation from remote authenticated users by leveraging the CSV user import function. This leads to obtaining remote code execution under the context of the Windows SYSTEM account in a default installation.
Discovered in: 15.1.6 (current as of August 2018)
Fixed in: Serv-U 15.1.6 Hotfix 2