ActiveX Control Vulnerability in Symantec Backup Exec for Windows Server
CVE-2007-6017
Currently unrated
Key Information:
- Vendor
Symantec
- Vendor
- CVE Published:
- 29 February 2008
What is CVE-2007-6017?
The PVATLCalendar.PVCalendar.1 ActiveX control in the Media Server component of Symantec Backup Exec for Windows Server exposes a vulnerability through its unsafe Save method. This allows remote attackers to initiate a denial of service by crashing the browser or gain the capability to create or overwrite arbitrary files using manipulated string values. Notably, the vendor indicates that while authenticated user involvement is suggested, attackers can exploit client machines with this control loaded without needing any authentication.