VTS24-002
Security Advisory affecting Backup Exec
Revision History
- 1.0: April 15, 2024: Initial version
Issues
Issue 1: Arbitrary File Delete
The Backup Exec Deduplication Multi-threaded Streaming Agent can be leveraged to perform arbitrary file deletion on protected files.
- CVE-ID: CVE-2024-33671
- Severity: High
- CVSS v3.1 Base Score 7.7 (AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H)
- Affected Versions:: 21.0, 21.1, 21,2, 21,3, 21.4, 22.0, 22.1, 22.2
- Recommended action: Upgrade to Version 23.0 (no HotFix needed) or
Upgrade to version 22.2 and apply HotFix 917391 from the Download Center. - Mitigation: Restrict access to the boost_interprocess directory (C:\ProgramData\boost_interprocess) to local administrator users only
Issue 2: Insecure DLL loading
Several issues involving loading of insecure DLLs were addressed in this advisory.
- CVE-ID: CVE-2024-33673
- Severity: High
- CVSS v3.1 Base Score 7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
- Affected Versions:: 21.0, 21.1, 21,2, 21,3, 21.4, 22.0, 22.1, 22.2
- Recommended action: Upgrade to Version 23.0 (no HotFix needed) or
Upgrade to version 22.2 and apply HotFix 917391 from the Download Center.
Mitigation:
- The issue is mitigated if non-admin Windows users DO NOT have access to create files in the DLL search path.
- Please see Microsoft documentation for DLL search order. https://learn.microsoft.com/en-us/windows/win32/dlls/dynamic-link-library-search-order
Acknowledgement
Veritas would like to thank the Lockheed Martin Red Team for notifying us about these issues.
Questions
For questions or problems regarding these vulnerabilities please contact Veritas Technical Support (https://www.veritas.com/support)
Disclaimer
THE SECURITY ADVISORY IS PROVIDED "AS IS" AND ALL EXPRESS OR IMPLIED CONDITIONS, REPRESENTATIONS AND WARRANTIES, INCLUDING ANY IMPLIED WARRANTY OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE OR NON-INFRINGEMENT, ARE DISCLAIMED, EXCEPT TO THE EXTENT THAT SUCH DISCLAIMERS ARE HELD TO BE LEGALLY INVALID. VERITAS TECHNOLOGIES LLC SHALL NOT BE LIABLE FOR INCIDENTAL OR CONSEQUENTIAL DAMAGES IN CONNECTION WITH THE FURNISHING, PERFORMANCE, OR USE OF THIS DOCUMENTATION. THE INFORMATION CONTAINED IN THIS DOCUMENTATION IS SUBJECT TO CHANGE WITHOUT NOTICE.
Veritas Technologies LLC
2625 Augustine Drive
Santa Clara, CA 95054