PT-2024-3953 · Veritas · Veritas System Recovery
Published
2024-05-12
·
Updated
2024-09-26
·
CVE-2024-35204
CVSS v3.1
8.4
High
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Veritas System Recovery versions prior to 23.3 Hotfix
Description
The issue is related to incorrect permissions for the Veritas System Recovery folder, allowing low-privileged users to conduct attacks. Exploitation of this issue may enable an attacker to elevate their privileges by creating a specially crafted file in an arbitrary location on the file system.
Recommendations
For versions prior to 23.3 Hotfix, update to version 23.3 Hotfix or later to resolve the issue. As a temporary workaround, consider restricting access to the Veritas System Recovery folder to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Veritas System Recovery