PT-2016-3247 · Commvault · Commvault
Wchen-R7
·
Publicado
2016-12-08
·
Atualizado
2019-10-03
·
CVE-2017-18044
CVSS v3.1
10
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Commvault versions prior to v11 SP6
Description
A Command Injection issue was discovered in the ContentStore/Base/CVDataPipe.dll of Commvault. The issue arises from a message parsing function inside the Commvault service that does not properly validate the input of an incoming string before passing it to CreateProcess. This allows a specially crafted message to inject commands that will be executed on the target operating system. Exploitation of this issue does not require authentication and can lead to SYSTEM level privilege on any system running the cvd daemon.
Recommendations
For Commvault versions prior to v11 SP6, update to version v11 SP6 or later to resolve the issue. As a temporary workaround, consider restricting access to the cvd daemon to minimize the risk of exploitation.
Exploit
Correção
OS Command Injection
Command Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Commvault