An issue was discovered in Veritas NetBackup before 10.0 on Windows. A vulnerability in the way the client validates the path to a DLL prior to loading may allow a lower-level user to elevate privileges and compromise the system.
References
Configurations
History
21 Nov 2024, 07:55
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.veritas.com/content/support/en_US/security/VTS23-006 - |
29 Apr 2023, 01:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Summary | An issue was discovered in Veritas NetBackup before 10.0 on Windows. A vulnerability in the way the client validates the path to a DLL prior to loading may allow a lower-level user to elevate privileges and compromise the system. |
27 Mar 2023, 16:08
Type | Values Removed | Values Added |
---|---|---|
First Time |
Veritas
Veritas netbackup |
|
CWE | CWE-427 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
References | (MISC) https://www.veritas.com/content/support/en_US/security/VTS22-010#M2 - Vendor Advisory | |
CPE | cpe:2.3:a:veritas:netbackup:*:*:*:*:*:*:*:* |
23 Mar 2023, 04:17
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-03-23 04:17
Updated : 2025-02-25 20:15
NVD link : CVE-2023-28759
Mitre link : CVE-2023-28759
CVE.ORG link : CVE-2023-28759
JSON object : View
Products Affected
veritas
- netbackup
CWE
CWE-427
Uncontrolled Search Path Element