Impact
The vulnerability lies in an unsafe deserialization routine within Commvault Content Extractor that allows untrusted data to be processed as executable code. This flaw can enable an attacker to inject malicious payloads that bypass normal privilege checks, effectively giving them escalated access on the target system. The weakness is characterized by the handling of deserialized objects, which directly compromises integrity and confidentiality of privileged operations.
Affected Systems
Affected vendors include Commvault, specifically the CommVault Cloud product line. No discrete product or version identifiers are listed, so any deployment of the Content Extractor component that remains on the original release is potentially vulnerable. Users should verify their deployment against the latest maintenance release noted in the advisory.
Risk and Exploitability
The CVSS base score of 7.3 indicates a high severity with significant impact. The EPSS score is not available, so the current exploitation probability is uncertain, but the absence of a KEV listing suggests no widely reported exploitation at this time. Attackers would typically need to supply a crafted payload to the vulnerable deserialization point, which requires either a user interaction or ability to influence the data stream. Until the fixed release is applied, the vulnerability could be exploited.
OpenCVE Enrichment