Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-54818 | A DLL injection vulnerability exists in Commvault for Windows 11.20.0, 11.28.0, 11.32.0, 11.34.0, and 11.36.0. During the installation of maintenance updates, an attacker with local access may exploit uncontrolled search path or DLL loading behavior to execute arbitrary code with elevated privileges. The vulnerability has been resolved in versions 11.20.202, 11.28.124, 11.32.65, 11.34.37, and 11.36.15. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Sat, 22 Nov 2025 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Commvault
Commvault commvault |
|
| CPEs | cpe:2.3:a:commvault:commvault:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Commvault
Commvault commvault |
Fri, 25 Jul 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 25 Jul 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A DLL injection vulnerability exists in Commvault for Windows 11.20.0, 11.28.0, 11.32.0, 11.34.0, and 11.36.0. During the installation of maintenance updates, an attacker with local access may exploit uncontrolled search path or DLL loading behavior to execute arbitrary code with elevated privileges. The vulnerability has been resolved in versions 11.20.202, 11.28.124, 11.32.65, 11.34.37, and 11.36.15. | |
| Title | Commvault 11.20.0 - 11.36.0 Windows Maintenance Installer DLL Injection | |
| Weaknesses | CWE-427 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-11-22T12:20:44.890Z
Reserved: 2025-07-23T20:30:07.057Z
Link: CVE-2024-13976
Updated: 2025-07-25T17:49:30.981Z
Status : Awaiting Analysis
Published: 2025-07-25T16:15:27.690
Modified: 2025-07-29T14:14:55.157
Link: CVE-2024-13976
No data.
OpenCVE Enrichment
No data.
EUVD