CVE-2007-5331

CWE-94Code Injection3 documents3 sources
Severity
10.0CRITICAL
EPSS
18.1%
top 4.82%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 13
Latest updateMay 1

Description

Queue.dll for the message queuing service (LQserver.exe) in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, allows remote attackers to execute arbitrary code via a malformed ONRPC protocol request for operation 0x76, which causes ARCserve Backup to dereference arbitrary pointers.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-2954-hh3h-2236: Queue2022-05-01
CVEList
CVE-2007-5331: Queue2007-10-13