Deserialization Vulnerability in Veritas Enterprise Vault Service
CVE-2021-44678
9.8CRITICAL
What is CVE-2021-44678?
A deserialization vulnerability exists in Veritas Enterprise Vault due to insecure handling of .NET Remoting TCP services. On startup, the application initiates several services that communicate over random ports, which can be exploited by attackers. These services can be targeted through both TCP remoting and local IPC communications on the Enterprise Vault Server. It is crucial for administrators to follow the vendor's security guidance to mitigate risks, including proper configuration of firewalls and service settings as outlined in Veritas's security alert.