PT-2024-3953 · Veritas · Veritas System Recovery

Published

2024-05-12

·

Updated

2024-09-26

·

CVE-2024-35204

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Veritas System Recovery versions prior to 23.3 Hotfix
Description The issue is related to incorrect permissions for the Veritas System Recovery folder, allowing low-privileged users to conduct attacks. Exploitation of this issue may enable an attacker to elevate their privileges by creating a specially crafted file in an arbitrary location on the file system.
Recommendations For versions prior to 23.3 Hotfix, update to version 23.3 Hotfix or later to resolve the issue. As a temporary workaround, consider restricting access to the Veritas System Recovery folder to minimize the risk of exploitation.

Fix

Weakness Enumeration

Related Identifiers

BDU:2024-04367
CVE-2024-35204

Affected Products

Veritas System Recovery