Heap-based Buffer Overflow in Symantec Veritas Storage Foundation
CVE-2008-0638
Currently unrated
Summary
A heap-based buffer overflow vulnerability exists in the Veritas Enterprise Administrator service (vxsvc.exe) of Symantec's Veritas Storage Foundation 5.0. This flaw allows remote attackers to exploit the service by sending specially crafted packets with a size field that is not properly validated against the buffer size. Successful exploitation can lead to arbitrary code execution on the affected system, posing significant risks to data integrity and system security. Users and administrators are strongly advised to apply the necessary patches to mitigate this vulnerability.
References
EPSS Score
20% chance of being exploited in the next 30 days.
Timeline
Vulnerability published
Vulnerability Reserved