{"api_version":"1","generated_at":"2026-07-23T06:34:30+00:00","cve":"CVE-2007-2279","urls":{"html":"https://cve.report/CVE-2007-2279","api":"https://cve.report/api/cve/CVE-2007-2279.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-2279","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-2279"},"summary":{"title":"CVE-2007-2279","description":"The Scheduler Service (VxSchedService.exe) in Symantec Storage Foundation for Windows 5.0 allows remote attackers to bypass authentication and execute arbitrary code via certain requests to the service socket that create (1) PreScript or (2) PostScript registry values under Veritas\\VxSvc\\CurrentVersion\\Schedules specifying future command execution.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-06-04 16:30:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-264","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"9.3","severity":"","vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.securitytracker.com/id?1018188","name":"http://www.securitytracker.com/id?1018188","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker.com Archives - Symantec VERITAS Storage Foundation Windows Scheduler Service Lets Remote Users Execute Arbitrary Commands","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/24194","name":"http://www.securityfocus.com/bid/24194","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Symantec Storage Foundation VxSchedService.EXE Scheduler Service Authentication Bypass Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/25537","name":"http://secunia.com/advisories/25537","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Symantec Veritas Storage Foundation Scheduler Service Authentication Bypass - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.symantec.com/avcenter/security/Content/2007.06.01.html","name":"http://www.symantec.com/avcenter/security/Content/2007.06.01.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Symantec Storage Foundation for Windows Volume Manager: Authentication Bypass and Potential Code Execution in Scheduler Service","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/470562/100/0/threaded","name":"http://www.securityfocus.com/archive/1/470562/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/34680","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/34680","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/36104","name":"http://osvdb.org/36104","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.vupen.com/english/advisories/2007/2035","name":"http://www.vupen.com/english/advisories/2007/2035","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://seer.entsupport.symantec.com/docs/288627.htm","name":"http://seer.entsupport.symantec.com/docs/288627.htm","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Symantec Security Advisory SYM07-009 - Veritas Storage Foundation 5.0 for Windows:  Authentication Bypass and Potential Code Execution in Scheduler Service","mime":"text/html","httpstatus":"400","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-2279","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-2279","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"2279","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"symantec","cpe5":"veritas_storage_foundation","cpe6":"5.0","cpe7":"*","cpe8":"windows","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T13:33:28.339Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.symantec.com/avcenter/security/Content/2007.06.01.html"},{"name":"25537","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/25537"},{"name":"20070605 TPTI-07-08: Symantec Veritas Storage Foundation Scheduler Service Authentication Bypass Vulnerability","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/470562/100/0/threaded"},{"name":"1018188","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1018188"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://seer.entsupport.symantec.com/docs/288627.htm"},{"name":"36104","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/36104"},{"name":"24194","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/24194"},{"name":"ADV-2007-2035","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/2035"},{"name":"symantec-scheduler-security-bypass(34680)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/34680"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-06-01T00:00:00.000Z","descriptions":[{"lang":"en","value":"The Scheduler Service (VxSchedService.exe) in Symantec Storage Foundation for Windows 5.0 allows remote attackers to bypass authentication and execute arbitrary code via certain requests to the service socket that create (1) PreScript or (2) PostScript registry values under Veritas\\VxSvc\\CurrentVersion\\Schedules specifying future command execution."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-16T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://www.symantec.com/avcenter/security/Content/2007.06.01.html"},{"name":"25537","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/25537"},{"name":"20070605 TPTI-07-08: Symantec Veritas Storage Foundation Scheduler Service Authentication Bypass Vulnerability","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/470562/100/0/threaded"},{"name":"1018188","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1018188"},{"tags":["x_refsource_CONFIRM"],"url":"http://seer.entsupport.symantec.com/docs/288627.htm"},{"name":"36104","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/36104"},{"name":"24194","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/24194"},{"name":"ADV-2007-2035","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/2035"},{"name":"symantec-scheduler-security-bypass(34680)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/34680"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-2279","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The Scheduler Service (VxSchedService.exe) in Symantec Storage Foundation for Windows 5.0 allows remote attackers to bypass authentication and execute arbitrary code via certain requests to the service socket that create (1) PreScript or (2) PostScript registry values under Veritas\\VxSvc\\CurrentVersion\\Schedules specifying future command execution."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://www.symantec.com/avcenter/security/Content/2007.06.01.html","refsource":"CONFIRM","url":"http://www.symantec.com/avcenter/security/Content/2007.06.01.html"},{"name":"25537","refsource":"SECUNIA","url":"http://secunia.com/advisories/25537"},{"name":"20070605 TPTI-07-08: Symantec Veritas Storage Foundation Scheduler Service Authentication Bypass Vulnerability","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/470562/100/0/threaded"},{"name":"1018188","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1018188"},{"name":"http://seer.entsupport.symantec.com/docs/288627.htm","refsource":"CONFIRM","url":"http://seer.entsupport.symantec.com/docs/288627.htm"},{"name":"36104","refsource":"OSVDB","url":"http://osvdb.org/36104"},{"name":"24194","refsource":"BID","url":"http://www.securityfocus.com/bid/24194"},{"name":"ADV-2007-2035","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/2035"},{"name":"symantec-scheduler-security-bypass(34680)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/34680"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-2279","datePublished":"2007-06-04T16:00:00.000Z","dateReserved":"2007-04-26T00:00:00.000Z","dateUpdated":"2024-08-07T13:33:28.339Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-06-04 16:30:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-264","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":8.6,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:symantec:veritas_storage_foundation:5.0:*:windows:*:*:*:*:*","matchCriteriaId":"10C7B114-73FB-4294-8E2E-94B5CB63750D"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"2279","Ordinal":"1","Title":"CVE-2007-2279","CVE":"CVE-2007-2279","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"2279","Ordinal":"1","NoteData":"The Scheduler Service (VxSchedService.exe) in Symantec Storage Foundation for Windows 5.0 allows remote attackers to bypass authentication and execute arbitrary code via certain requests to the service socket that create (1) PreScript or (2) PostScript registry values under Veritas\\VxSvc\\CurrentVersion\\Schedules specifying future command execution.","Type":"Description","Title":"CVE-2007-2279"},{"CveYear":"2007","CveId":"2279","Ordinal":"2","NoteData":"2007-06-04","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"2279","Ordinal":"3","NoteData":"2018-10-16","Type":"Other","Title":"Modified"}]}}}