VTS24-001
Security Advisory affecting NetBackup on Windows
Revision History
- 1.0: April 15, 2024: Initial version
- 1.1: May 8, 2024: Additional Recommended Action for 10.0.0.1 and 9.1.0.1
- 1.2: May 22, 2024: Include EEB Bundle information available for 10.0.0.1 and 9.1.0.1
Issue 1: Arbitrary File Delete
The Multi-Threaded Agent used in NetBackup can be leveraged to perform arbitrary file deletion on protected files.
CVE-ID: CVE-2024-33672
Severity: High
CVSS v3.1 Base Score 7.7 (AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H)
CWE-427 Uncontrolled Search Path Element
Affected Components: Only on Microsoft Windows Operating Systems - Primary Server, Media Server and Clients
Affected Versions: 10.3.0.1, 10.3, 10.2.0.1, 10.2, 10.1.1, 10.1, 10.0.0.1, 10.0, 9.1.0.1, 9.1, 8.3.0.2.
Note: Older unsupported versions may also be affected.
Recommended Action:
- Upgrade to version 10.4 (no EEB needed), or
- Upgrade to version 10.3.0.1 and apply 10.3.0.1 MSDP EEB Bundle from Download Center, or
- Upgrade to version 10.2.0.1 and apply 10.2.0.1 MSDP EEB Bundle from Download Center, or
- Upgrade to version 10.1.1 and apply 10.1.1 MSDP EEB Bundle from Download Center.
- For Version 10.0.0.1 apply 10.0.0.1 MSDP EEB Bundle from Download Center
- For version 9.1.0.1 apply 9.1.0.1 MSDP EEB Bundle from Download Center
Mitigation: Restrict access to the boost_interprocess directory (C:\ProgramData\boost_interprocess) to local administrator users only
Acknowledgement
Veritas would like to thank the Lockheed Martin Red Team for notifying us about this issue.
Questions
For questions or problems regarding these vulnerabilities please contact Veritas Technical Support (https://www.veritas.com/support/en_US/contact-us)
Disclaimer
THE SECURITY ADVISORY IS PROVIDED "AS IS" AND ALL EXPRESS OR IMPLIED CONDITIONS, REPRESENTATIONS AND WARRANTIES, INCLUDING ANY IMPLIED WARRANTY OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE OR NON-INFRINGEMENT, ARE DISCLAIMED, EXCEPT TO THE EXTENT THAT SUCH DISCLAIMERS ARE HELD TO BE LEGALLY INVALID. VERITAS TECHNOLOGIES LLC SHALL NOT BE LIABLE FOR INCIDENTAL OR CONSEQUENTIAL DAMAGES IN CONNECTION WITH THE FURNISHING, PERFORMANCE, OR USE OF THIS DOCUMENTATION. THE INFORMATION CONTAINED IN THIS DOCUMENTATION IS SUBJECT TO CHANGE WITHOUT NOTICE.
Veritas Technologies LLC
2625 Augustine Drive
Santa Clara, CA 95054