Arbitrary File Deletion Vulnerability in Veritas Backup Exec Before 22.2 HotFix 917391
CVE-2024-33671

7.1HIGH

Key Information:

Vendor

Veritas

Vendor
CVE Published:
26 April 2024

What is CVE-2024-33671?

A vulnerability has been identified in Veritas Backup Exec that allows attackers to exploit the Deduplication Multi-threaded Streaming Agent, leading to arbitrary file deletion of protected files. This flaw affects versions preceding 22.2 HotFix 917391, potentially exposing critical data to unauthorized removal, which can severely impact organizational data integrity and security. It is essential for users to apply the necessary updates and maintain vigilance to protect their data from such exploitation.

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.