An issue was discovered in Veritas NetBackup before 10.5. This only applies to NetBackup components running on a Windows Operating System. If a user executes specific NetBackup commands or an attacker uses social engineering techniques to impel the user to execute the commands, a malicious DLL could be loaded, resulting in execution of the attacker's code in the user's security context.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-45979 An issue was discovered in Veritas NetBackup before 10.5. This only applies to NetBackup components running on a Windows Operating System. If a user executes specific NetBackup commands or an attacker uses social engineering techniques to impel the user to execute the commands, a malicious DLL could be loaded, resulting in execution of the attacker's code in the user's security context.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 30 Apr 2025 16:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:veritas:netbackup:*:*:*:*:*:*:*:*

Tue, 19 Nov 2024 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Veritas
Veritas netbackup
Weaknesses CWE-94
CPEs cpe:2.3:a:veritas:netbackup:-:*:*:*:*:*:*:*
Vendors & Products Veritas
Veritas netbackup
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 18 Nov 2024 05:45:00 +0000

Type Values Removed Values Added
Description An issue was discovered in Veritas NetBackup before 10.5. This only applies to NetBackup components running on a Windows Operating System. If a user executes specific NetBackup commands or an attacker uses social engineering techniques to impel the user to execute the commands, a malicious DLL could be loaded, resulting in execution of the attacker's code in the user's security context.
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AC:L/AV:L/A:H/C:H/I:H/PR:N/S:U/UI:R'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-11-19T15:43:05.461Z

Reserved: 2024-11-18T00:00:00

Link: CVE-2024-52945

cve-icon Vulnrichment

Updated: 2024-11-19T15:42:58.848Z

cve-icon NVD

Status : Analyzed

Published: 2024-11-18T06:15:06.250

Modified: 2025-04-30T16:19:12.327

Link: CVE-2024-52945

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.