Remote Code Execution Vulnerability in Veritas Enterprise Vault
CVE-2021-44682

9.8CRITICAL

Key Information:

Vendor
Veritas
Vendor
CVE Published:
6 December 2021

Summary

A security issue exists in Veritas Enterprise Vault that affects versions up to 14.1.2. During startup, the application initiates several services which listen on random .NET Remoting TCP ports, exposing the system to command execution from client applications. Attackers can exploit this vulnerability through both TCP remoting services and local IPC services, leveraging the deserialization behavior endemic to the .NET Remoting framework. Proper configuration of servers and firewalls, as outlined in Veritas's security alert, is crucial to mitigate these risks.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.