An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24334. It allows remote attackers to execute arbitrary code because untrusted data, received on a .NET Remoting TCP port, is deserialized.
References
Link | Resource |
---|---|
https://www.veritas.com/content/support/en_US/security/VTS24-014 | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2024-11-24 21:15
Updated : 2024-11-29 20:54
NVD link : CVE-2024-53909
Mitre link : CVE-2024-53909
CVE.ORG link : CVE-2024-53909
JSON object : View
Products Affected
veritas
- enterprise_vault
CWE
CWE-502
Deserialization of Untrusted Data