CVE-2017-8895
60Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 71%
from disclosure to weapon50 days
Published on NVDMay 10
1st PoC+50d
metasploitMay 10
exploitation probability
71%top 1% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
In Veritas Backup Exec 2014 before build 14.1.1187.1126, 15 before build 14.2.1180.3160, and 16 before FP1, there is a use-after-free vulnerability in multiple agents that can lead to a denial of service or remote code execution. An unauthenticated attacker can use this vulnerability to crash the agent or potentially take control of the agent process and then the system it is running on.
Affected products
n/a · n/apublic PoCs found — 2✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/42282cve_referencewww.exploit-db.com/exploits/42282/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.