Arbitrary Code Execution Vulerability in Veritas Enterprise Vault Before 15.2
CVE-2024-53912

9.8CRITICAL

Key Information:

Vendor
Veritas
Vendor
CVE Published:
24 November 2024

Summary

A vulnerability in the server component of Veritas Enterprise Vault prior to version 15.2 allows remote attackers to exploit deserialization of untrusted data received on a .NET Remoting TCP port. When successfully exploited, this vulnerability enables attackers to execute arbitrary code on the affected server. Organizations using affected versions should prioritize timely updates to mitigate this security risk. For detailed remediation steps and further advisory, refer to the official security update from Veritas.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.