Veritas Backup Exec Server Remote Registry Access Vulnerability
BID:14020
Info
Veritas Backup Exec Server Remote Registry Access Vulnerability
| Bugtraq ID: | 14020 |
| Class: | Access Validation Error |
| CVE: |
CVE-2005-0771 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 22 2005 12:00AM |
| Updated: | Jul 12 2009 04:06PM |
| Credit: | Discovery of this issue is credited to Pedram Amini, iDEFENSE Labs. |
| Vulnerable: |
Veritas Software Backup Exec for Windows Servers 10.0 rev. 5484 Veritas Software Backup Exec for Windows Servers 9.1 rev. 4691 Veritas Software Backup Exec for Windows Servers 9.0 rev. 4454 Veritas Software Backup Exec for Windows Servers 9.0 rev. 4367 |
| Not Vulnerable: |
Veritas Software Backup Exec for Windows Servers 10.0 rev. 5520 |
Discussion
Veritas Backup Exec Server Remote Registry Access Vulnerability
VERITAS Backup Exec for Windows Servers is prone to an access validation vulnerability.
The issue may be leveraged by a remote attacker to gain 'Administrator' access to the vulnerable computer's registry. This access may be further leveraged to gain unfettered access to the target computer.
VERITAS Backup Exec for Windows Servers is prone to an access validation vulnerability.
The issue may be leveraged by a remote attacker to gain 'Administrator' access to the vulnerable computer's registry. This access may be further leveraged to gain unfettered access to the target computer.
Exploit / POC
Veritas Backup Exec Server Remote Registry Access Vulnerability
An exploit (backupexec_registry.pm) as part of the Metasploit Framework has been released.
An exploit (backupexec_registry.pm) as part of the Metasploit Framework has been released.
Solution / Fix
Veritas Backup Exec Server Remote Registry Access Vulnerability
Solution:
The vendor has released an advisory (VX05-003) and fixes to address this issue:
Veritas Software Backup Exec for Windows Servers 10.0 rev. 5484
Veritas Software Backup Exec for Windows Servers 9.0 rev. 4367
Veritas Software Backup Exec for Windows Servers 9.0 rev. 4454
Veritas Software Backup Exec for Windows Servers 9.1 rev. 4691
Solution:
The vendor has released an advisory (VX05-003) and fixes to address this issue:
Veritas Software Backup Exec for Windows Servers 10.0 rev. 5484
-
Veritas VERITAS Backup Exec 10.0 rev. 5484 for Windows Servers - upgrade to Backup Exec 10.0 rev. 5520
http://support.veritas.com/docs/277181 -
Veritas VERITAS Backup Exec 10.0 rev. 5484 for Windows Servers Hotfix 24
http://support.veritas.com/docs/275514
Veritas Software Backup Exec for Windows Servers 9.0 rev. 4367
-
Veritas VERITAS Backup Exec 9.0 rev. 4367 for Windows Servers Hotfix 21
http://support.veritas.com/docs/276156
Veritas Software Backup Exec for Windows Servers 9.0 rev. 4454
-
Veritas VERITAS Backup Exec 9.0 rev. 4454 for Windows Servers Hotfix 31
http://support.veritas.com/docs/275911
Veritas Software Backup Exec for Windows Servers 9.1 rev. 4691
-
Veritas VERITAS Backup Exec 9.1 rev. 4691 for Windows Servers Hotfix 52
http://support.veritas.com/docs/275909
References
Veritas Backup Exec Server Remote Registry Access Vulnerability
References:
References:
- Veritas Backup Exec Server Remote Registry Access Vulnerability (iDEFENSE)
- Veritas Homepage (Veritas Software)
- Vulnerability Note VU#584505 (CERT)
- VX05-003 - VERITAS Backup Exec Server Remote Registry Access Vulnerability (Veritas Software)