CVE-2017-8895
In Veritas Backup Exec 2014 before build 14.1.1187.1126, 15 before build 14.2.1180.3160, and 16 before FP1, there is a use-after-free vulnerability in multiple agents that can lead to a denial of service or remote code execution.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 71.0%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
In Veritas Backup Exec 2014 before build 14.1.1187.1126, 15 before build 14.2.1180.3160, and 16 before FP1, there is a use-after-free vulnerability in multiple agents that can lead to a denial of service or remote code execution. An unauthenticated attacker can use this vulnerability to crash the agent or potentially take control of the agent process and then the system it is running on.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 71.00% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-416
- Affected
- veritas/backup exec
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/bid/98386Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1038561Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/42282/Third Party Advisory, VDB Entry
- https://www.veritas.com/content/support/en_US/security/VTS17-006.html#Issue1Patch, Vendor Advisory
- http://www.securityfocus.com/bid/98386Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1038561Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/42282/Third Party Advisory, VDB Entry
- https://www.veritas.com/content/support/en_US/security/VTS17-006.html#Issue1Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.