The LDBserver service in the server in CA ARCserve Backup 11.1 up to and including 12.0 on Windows allows remote malicious users to execute arbitrary code via a handle_t argument to an RPC endpoint in which the argument refers to an incompatible procedure.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
broadcom arcserve_backup r12.0 |
||
ca arcserve_backup r11.5 |
||
ca arcserve_backup r11.1 |