Site icon TheCyberThrone

Veritas fixes a Privilege Escalation Bug in its Backup Application

Advertisements

Veritas has addressed a privilege escalation vulnerability impacting its NetBackup software on Windows systems. This vulnerability, which affects NetBackup’s primary server, media server, and client components, exposes Windows-based NetBackup installations to potential privilege escalation attacks.

The vulnerability still didn’t have any CVE assigned, but has a CVSS score of 7.8, The attack stems on an attacker gaining write access to the root drive where NetBackup is installed. If a NetBackup user executes certain commands or is manipulated through social engineering tactics, the malicious DLL could be loaded, executing the attacker’s code within the user’s security context.

Veritas has outlined a broad spectrum of affected versions, including but not limited to:

Advertisements

To mitigate this vulnerability, Veritas has recommended two primary paths for remediation:

  1. Upgrade to NetBackup Version 10.5: This new release addresses the vulnerability.
  2. Apply Hotfixes for Supported Older Versions: Veritas advises upgrading to NetBackup Version 10.4.0.1 or 10.3.0.1 and applying the hotfix from Veritas’ download center to secure these installations.

If immediate upgrade is not possible, Veritas has offered an alternate mitigation method. Administrators are advised to:

For more details, refer to the blog

Exit mobile version