Remote Code Execution Vulnerability in Veritas Enterprise Vault
CVE-2021-44682
9.8CRITICAL
What is CVE-2021-44682?
A security issue exists in Veritas Enterprise Vault that affects versions up to 14.1.2. During startup, the application initiates several services which listen on random .NET Remoting TCP ports, exposing the system to command execution from client applications. Attackers can exploit this vulnerability through both TCP remoting services and local IPC services, leveraging the deserialization behavior endemic to the .NET Remoting framework. Proper configuration of servers and firewalls, as outlined in Veritas's security alert, is crucial to mitigate these risks.