Heap-based Buffer Overflow in Symantec Backup Exec
CVE-2007-3509
Currently unrated
What is CVE-2007-3509?
The vulnerability is a heap-based buffer overflow found in the RPC (Remote Procedure Call) subsystem of Symantec Backup Exec. Attackers can exploit this flaw by sending specially crafted ncacn_ip_tcp requests, leading to a process exit and potentially enabling arbitrary code execution. This vulnerability affects versions 10.0, 10d, and 11d of the software, potentially exposing systems to remote attackers seeking to compromise system integrity.