← volver
CVE-2020-37045

NetBackup 7.0 - 'NetBackup INET Daemon' Unquoted Service Path

CVSS 8.5 HIGHEPSS 0.1%CWE-428
Veritas NetBackup 7.0 contains an unquoted service path vulnerability in the NetBackup INET Daemon service that allows local users to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files\Veritas\NetBackup\bin\bpinetd.exe to inject malicious code that would execute with elevated LocalSystem privileges.
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Productos afectados
Veritas · NetBackup

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →