Description

Veritas has released a security advisory for a critical privilege escalation vulnerability impacting its NetBackup software on Windows systems. This flaw affects NetBackup’s primary server, media server, and client components, putting Windows-based installations at risk for privilege escalation attacks. Veritas explains that “NetBackup primary server, media server, and clients on Windows OS may be susceptible to attacks that enable privilege escalation.” The exploit requires that an attacker obtain write access to the drive where NetBackup is installed. With this access, an attacker could place a malicious DLL file on the system. If the NetBackup user runs specific commands or falls victim to social engineering, this DLL could be loaded, allowing the attacker’s code to run with the user’s permissions. This vulnerability, which does not yet have a CVE number, has been assigned a CVSS score of 7.8, denoting high severity. The advisory specifies that the vulnerability only impacts NetBackup components running on Windows OS, leaving other operating systems unaffected. The advisory lists several affected versions, including NetBackup Client, Primary Server, and Media Server on versions 10.4.0.1, 10.4, 10.3.0.1, 10.3, 10.2.0.1, 10.2, 10.1.1, 10.1, 10.0.0.1, and 10.0, with older, unsupported versions potentially vulnerable as well.