In Veritas System Recovery before 16 SP1, there is a DLL hijacking vulnerability in the patch installer if an attacker has write access to the directory from which the product is executed.
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/97483 | Third Party Advisory VDB Entry |
https://www.veritas.com/content/support/en_US/security/VTS17-001.html#Issue1 | Vendor Advisory |
http://www.securityfocus.com/bid/97483 | Third Party Advisory VDB Entry |
https://www.veritas.com/content/support/en_US/security/VTS17-001.html#Issue1 | Vendor Advisory |
Configurations
History
21 Nov 2024, 03:31
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.securityfocus.com/bid/97483 - Third Party Advisory, VDB Entry | |
References | () https://www.veritas.com/content/support/en_US/security/VTS17-001.html#Issue1 - Vendor Advisory |
Information
Published : 2017-04-05 20:59
Updated : 2024-11-21 03:31
NVD link : CVE-2017-7444
Mitre link : CVE-2017-7444
CVE.ORG link : CVE-2017-7444
JSON object : View
Products Affected
veritas
- system_recovery
CWE