CVE-2007-0169
50Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 69%
from disclosure to weapon1205 days
Published on NVDJan 11
1st PoC+1205d
metasploitJan 11
exploitation probability
69%top 1% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Multiple buffer overflows in Computer Associates (CA) BrightStor ARCserve Backup 9.01 through 11.5, Enterprise Backup 10.5, and CA Server/Business Protection Suite r2 allow remote attackers to execute arbitrary code via RPC requests with crafted data for opnums (1) 0x2F and (2) 0x75 in the (a) Message Engine RPC service, or opnum (3) 0xCF in the Tape Engine service.
Affected products
n/a · n/apublic PoCs found — 1
exploitdbwww.exploit-db.com/exploits/16418unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=467http://osvdb.org/31327http://secunia.com/advisories/23648http://securitytracker.com/id?1017506https://exchange.xforce.ibmcloud.com/vulnerabilities/31433https://exchange.xforce.ibmcloud.com/vulnerabilities/31443http://supportconnectw.ca.com/public/storage/infodocs/babimpsec-notice.asphttp://www.kb.cert.org/vuls/id/151032http://www.kb.cert.org/vuls/id/180336http://www.securityfocus.com/archive/1/456618/100/0/threadedhttp://www.securityfocus.com/archive/1/456619/100/0/threadedhttp://www.securityfocus.com/archive/1/456711