Advisories Blog | G5 Cyber Security

EEYE-cabright.txt

eEye Digital Security has discovered a remote vulnerability in CA BrightStor ARCserve Backup Server that allows an attacker to execute arbitrary code as SYSTEM without any user interaction. The exploit is extremely reliable and can be successfully delivered either across the Internet or within local networks via a random TCP port that is disclosed by the BrightStor portmapper service on TCP/111.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/60042/EEYE-cabright.txt

Source: https://packetstormsecurity.com/files/60042/EEYE-cabright.txt.html

Exit mobile version