Arbitrary Code Execution Vulnerability in Veritas Enterprise Vault
CVE-2020-36164
9.3CRITICAL
Summary
A vulnerability in Veritas Enterprise Vault allows a low privileged user to create a malicious OpenSSL configuration file, which can lead to arbitrary code execution as the SYSTEM user upon service startup. This affects multiple components, including MTP Server and various archiving servers, potentially granting attackers administrative access to the system and its data.
References
CVSS V3.1
Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved