Code Execution Vulnerability in Veritas NetBackup and OpsCenter for Windows
CVE-2020-36163

9.3CRITICAL

Key Information:

Vendor
Veritas
Vendor
CVE Published:
6 January 2021

Summary

A security flaw was identified in Veritas NetBackup and OpsCenter versions through 8.3.0.1 that enables low privileged users on Windows systems to exploit the library loading mechanism utilized by NetBackup processes. Specifically, these processes, using Strawberry Perl, attempt to load libraries from directories that may not exist by default. If a malicious user creates a directory with a crafted library in one of these paths, they can execute arbitrary code with elevated privileges, potentially gaining SYSTEM or Administrator rights. This vulnerability has implications during installation and upgrades of the affected software and can be leveraged in normal operational activities, exposing sensitive data and installed applications.

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.