Arbitrary Code Execution Vulnerability in Veritas Enterprise Vault
CVE-2020-36164

9.3CRITICAL

Key Information:

Vendor
Veritas
Vendor
CVE Published:
6 January 2021

Summary

A vulnerability in Veritas Enterprise Vault allows a low privileged user to create a malicious OpenSSL configuration file, which can lead to arbitrary code execution as the SYSTEM user upon service startup. This affects multiple components, including MTP Server and various archiving servers, potentially granting attackers administrative access to the system and its data.

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.