SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2008-1786

The DSM gui_cm_ctrls ActiveX control (gui_cm_ctrls.ocx), as used in multiple CA products including BrightStor ARCServe Backup for Laptops and Desktops r11.5, Desktop Management Suite r11.1 through r11.2 C2; Unicenter r11.1 through r11.2 C2; and Desktop…

HIGH 9.3EPSS 6.82%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (6.82%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

The DSM gui_cm_ctrls ActiveX control (gui_cm_ctrls.ocx), as used in multiple CA products including BrightStor ARCServe Backup for Laptops and Desktops r11.5, Desktop Management Suite r11.1 through r11.2 C2; Unicenter r11.1 through r11.2 C2; and Desktop and Server Management r11.1 through r11.2 C2 allows remote attackers to execute arbitrary code via crafted function arguments.

CVSS 2.0
9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS
6.82% probability · 94th percentile
CISA KEV
Not listed
Weakness
CWE-94
Affected
computer associates/arcserve backup laptops and desktops · computer associates/desktop and server management · computer associates/desktop management suite · computer associates/unicenter asset management · computer associates/unicenter desktop management bundle · computer associates/unicenter remote control · computer associates/unicenter software delivery
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.