Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2023-28759: Security Advisory Impacting NetBackup Windows OS Clients

An issue was discovered in Veritas NetBackup before 10.0 on Windows. A vulnerability in the way the client validates the path to a DLL prior to loading may allow a lower-level user to elevate privileges and compromise the system.

CVE
#vulnerability#windows#microsoft

Revision History

  • 1.0: April 28, 2023 – Initial release

Issue: Privilege Escalation

A vulnerability in the way NetBackup Windows OS client validates the path to a DLL prior to loading may allow a lower level user to elevate privileges and compromise the system.

  • CVE ID: CVE-2023-28759
  • Severity: High
  • CVSS v3.1 Base Score: 7.8 (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
  • Impacted Components:
    • NetBackup Windows OS clients only, under the following conditions:
      • Microsoft Exchange, Microsoft SharePoint, and/or Enterprise Vault workloads are being protected
      • If these applications are installed on the client but not protected by NetBackup, the systems are not impacted
      • NetBackup clients protecting other workloads are not impacted
  • Affected Versions: All versions prior to 10.0
  • Recommended action:
    • NetBackup Windows OS clients: Upgrade to 10.0 or later
    • Disable nbdisco if above mentioned workloads are not protected by NetBackup

Questions

For questions or problems regarding this vulnerability please contact Veritas Technical Support (https://www.veritas.com/support)

Acknowledgement

Veritas would like the thank the Lockheed Martin Red Team for notifying us about this issue.

Disclaimer

THE SECURITY ADVISORY IS PROVIDED “AS IS” AND ALL EXPRESS OR IMPLIED CONDITIONS, REPRESENTATIONS AND WARRANTIES, INCLUDING ANY IMPLIED WARRANTY OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE OR NON-INFRINGEMENT, ARE DISCLAIMED, EXCEPT TO THE EXTENT THAT SUCH DISCLAIMERS ARE HELD TO BE LEGALLY INVALID. VERITAS TECHNOLOGIES LLC SHALL NOT BE LIABLE FOR INCIDENTAL OR CONSEQUENTIAL DAMAGES IN CONNECTION WITH THE FURNISHING, PERFORMANCE, OR USE OF THIS DOCUMENTATION. THE INFORMATION CONTAINED IN THIS DOCUMENTATION IS SUBJECT TO CHANGE WITHOUT NOTICE.

Veritas Technologies LLC
2625 Augustine Drive
Santa Clara, CA 95054

Related news

CVE-2023-28759: Hotfix for Security Advisory Impacting NetBackup Clients and Servers

An issue was discovered in Veritas NetBackup before 10.0. A vulnerability in the way NetBackup validates the path to a DLL prior to loading may allow a lower level user to elevate privileges and compromise the system.

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907