PT-2021-11940 · Veritas · Veritas System Recovery

Published

2021-01-06

·

Updated

2021-01-11

·

CVE-2020-36160

CVSS v3.1

9.3

Critical

VectorAC:L/AV:L/A:H/C:H/I:H/PR:N/S:C/UI:N
Name of the Vulnerable Software and Affected Versions: Veritas System Recovery versions prior to 21.2
Description: An issue in Veritas System Recovery allows a low-privileged user to create a malicious configuration file openssl.cnf in the C:usrlocalssl directory. This file can load a malicious OpenSSL engine, resulting in arbitrary code execution as SYSTEM when the service starts. This gives the attacker administrator access on the system, allowing them to access all data and installed applications. If the system is also an Active Directory domain controller, this can affect the entire domain.
Recommendations: For versions prior to 21.2, update to version 21.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the C:usrlocalssl directory to prevent low-privileged users from creating the malicious configuration file.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2020-36160

Affected Products

Veritas System Recovery