Remote Code Execution Vulnerability in Veritas Enterprise Vault
CVE-2021-44682
9.8CRITICAL
Summary
A security issue exists in Veritas Enterprise Vault that affects versions up to 14.1.2. During startup, the application initiates several services which listen on random .NET Remoting TCP ports, exposing the system to command execution from client applications. Attackers can exploit this vulnerability through both TCP remoting services and local IPC services, leveraging the deserialization behavior endemic to the .NET Remoting framework. Proper configuration of servers and firewalls, as outlined in Veritas's security alert, is crucial to mitigate these risks.
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved