PT-2026-5576 · Veritas · Netbackup
Published
2026-02-01
·
Updated
2026-02-01
·
CVE-2020-37045
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Veritas NetBackup versions 7.0
Description
The software contains an unquoted service path vulnerability in the NetBackup INET Daemon service. This allows local users to potentially execute arbitrary code. Attackers can exploit the unquoted path in
C:Program FilesVeritasNetBackupbinbpinetd.exe to inject malicious code that would execute with elevated LocalSystem privileges.Recommendations
Versions prior to 7.0 should be upgraded.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Netbackup