PT-2016-3247 · Commvault · Commvault

Wchen-R7

·

Publicado

2016-12-08

·

Atualizado

2019-10-03

·

CVE-2017-18044

CVSS v3.1

10

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Commvault versions prior to v11 SP6
Description A Command Injection issue was discovered in the ContentStore/Base/CVDataPipe.dll of Commvault. The issue arises from a message parsing function inside the Commvault service that does not properly validate the input of an incoming string before passing it to CreateProcess. This allows a specially crafted message to inject commands that will be executed on the target operating system. Exploitation of this issue does not require authentication and can lead to SYSTEM level privilege on any system running the cvd daemon.
Recommendations For Commvault versions prior to v11 SP6, update to version v11 SP6 or later to resolve the issue. As a temporary workaround, consider restricting access to the cvd daemon to minimize the risk of exploitation.

Exploit

Correção

OS Command Injection

Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2018-00335
CVE-2017-18044

Produtos afetados

Commvault