QID 376147

Date Published: 2021-12-10

QID 376147: Veritas NetBackup Vulnerabilities (VTS20-016)

Veritas NetBackup is an enterprise level heterogeneous backup and recovery suite.

Two vulnerabilities have been identified in Veritas NetBackup master servers, media servers, clients and OpsCenter servers on the Windows platform.
Due to these vulnerabilities, If a low privileged user on the Windows system creates an affected path with a library that NetBackup attempts to load, they can execute arbitrary code as SYSTEM or Administrator.

QID Detection Logic (Authenticated):
Operating Systems: Windows
The QID checks for the install path of Veritas NetBackup on Windows from the key HKLM\SOFTWARE\VERITAS\NetBackup\CurrentVersion value "VERSION". The QID then checks the version of the file <NetBackup\bin\libnbssl.dll>

CVE-2020-36169 and CVE-2020-36163: This gives the attacker administrator access on the system, allowing the attacker (by default) to access all data, to access all installed applications, etc.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 7.2 severity.
  • Solution
    The vendor has issued a fix for these vulnerabilities. Please refer to the vendor advisory VTS20-016 which addresses this issue.

    CVEs related to QID 376147

    Software Advisories
    Advisory ID Software Component Link
    VTS20-016 URL Logo www.veritas.com/content/support/en_US/security/VTS20-016